Browse Security Advisories
Moderate Security Advisories for https://github.com/sqlfluff/sqlfluff Clear Filters
Moderate
over 2 years ago
SQLFluff users with access to config file, using `libary_path` may call arbitrary python code
pypi
sqlfluff
Filter by Severity
Filter by Ecosystem
maven
3,339
packagist
3,024
pypi
2,058
npm
1,414
go
1,335
nuget
531
cargo
425
rubygems
418
hex
16
swift
11
actions
8
pub
3
Filter by Package
moodle/moodle
313
tensorflow
200
tensorflow-cpu
187
magento/community-edition
182
tensorflow-gpu
182
org.jenkins-ci.main:jenkins-core
148
com.liferay.portal:release.portal.bom
114
typo3/cms
112
org.apache.tomcat:tomcat
97
pimcore/pimcore
87
github.com/mattermost/mattermost/server/v8
86
com.liferay.portal:release.dxp.bom
81
typo3/cms-core
72
microweber/microweber
72
silverstripe/framework
66
phpmyadmin/phpmyadmin
56
dolibarr/dolibarr
55
drupal/core
52
github.com/usememos/memos
50
thorsten/phpmyfaq
47
magento/project-community-edition
47
apache-airflow
47
github.com/mattermost/mattermost-server
46
concrete5/concrete5
46
librenms/librenms
45
apache-superset
45
actionpack
43
Django
39
drupal/drupal
37
org.elasticsearch:elasticsearch
34
showdoc/showdoc
34
picklescan
34
mantisbt/mantisbt
33
org.keycloak:keycloak-core
32
github.com/grafana/grafana
31
craftcms/cms
31
github.com/mattermost/mattermost-server/v6
29
plone
29
symfony/symfony
29
nova
29
moin
27
intelliants/subrion
27
snipe/snipe-it
27
mautic/core
27
baserproject/basercms
26
shopware/platform
26
ansible
26
k8s.io/kubernetes
24
org.keycloak:keycloak-services
24
Plone
23
directus
23
github.com/hashicorp/vault
21
nilsteampassnet/teampass
21
github.com/answerdev/answer
21
gradio
20
mediawiki/core
20
froxlor/froxlor
20
grumpydictator/firefly-iii
20
matrix-synapse
20
django
20
github.com/cilium/cilium
19
shopware/core
19
shopware/shopware
19
org.apache.struts:struts2-core
19
DotNetNuke.Core
18
remdex/livehelperchat
18
salt
17
github.com/argoproj/argo-cd/v2
17
contao/core-bundle
17
getkirby/cms
17
rdiffweb
16
zendframework/zendframework1
16
github.com/docker/docker
16
prestashop/prestashop
16
rack
16
github.com/hashicorp/consul
16
yetiforce/yetiforce-crm
15
io.undertow:undertow-core
15
vyper
15
org.apache.tomcat.embed:tomcat-embed-core
15
github.com/hashicorp/nomad
15
org.opencms:opencms-core
15
org.apache.jspwiki:jspwiki-main
15
tinymce
14
org.xwiki.platform:xwiki-platform-oldcore
14
glance
14
puppet
14
nokogiri
13
tribalsystems/zenario
13
github.com/goharbor/harbor
13
org.springframework.security:spring-security-core
13
com.thoughtworks.xstream:xstream
13
keystone
13
com.jfinal:jfinal
13
com.liferay.portal:com.liferay.portal.impl
13
typo3/cms-backend
13
github.com/openfga/openfga
13
forkcms/forkcms
13
wallabag/wallabag
12
next
12
transformers
12
org.bouncycastle:bcprov-jdk15on
12
simplesamlphp/simplesamlphp
12
helm.sh/helm/v3
12
roundup
12
feehi/feehicms
11
github.com/rancher/rancher
11
tinymce/tinymce
11
@openzeppelin/contracts
11
laravel/framework
11
github.com/containerd/containerd
11
lavalite/cms
11
TinyMCE
11
genix/cms
11
activesupport
11
org.eclipse.jetty:jetty-server
11
ghost
11
github.com/ethereum/go-ethereum
11
@openzeppelin/contracts-upgradeable
11
getgrav/grav
11
ckeditor4
11
github.com/traefik/traefik/v2
11
ec-cube/ec-cube
11
github.com/argoproj/argo-cd
11
vite
11
vllm
11
surrealdb
10
notebook
10
francoisjacquet/rosariosis
10
com.vaadin:vaadin-bom
10
org.apache.solr:solr-core
10
org.springframework:spring-core
10
PaddlePaddle
10
OctoPrint
10
org.keycloak:keycloak-parent
10
bolt/bolt
10
aiohttp
10
zendframework/zendframework
10
electron
10
silverstripe/cms
10
opencart/opencart
10
org.apache.jspwiki:jspwiki-war
10
github.com/greenpau/caddy-security
10
bootstrap
10
phpoffice/phpspreadsheet
10
joplin
10
org.apache.nifi:nifi
10
fat_free_crm
10
horizon
9
angular
9
org.mortbay.jetty:jetty
9
pimcore/admin-ui-classic-bundle
9
calibreweb
9
org.apache.activemq:activemq-client
9
gogs.io/gogs
9
org.opencrx:opencrx-core-models
9
urllib3
9
code.gitea.io/gitea
9
swagger-ui
9
cakephp/cakephp
9
rubygems-update
9
org.jenkins-ci.plugins:script-security
9
org.jenkins-ci.plugins:git
9
open-webui
9
org.igniterealtime.openfire:parent
9
contao/contao
9
pyftpdlib
9
publify_core
9
wasmtime
9
github.com/traefik/traefik/v3
8
alextselegidis/easyappointments
8
flowise
8
validator
8
mlflow
8
Microsoft.ChakraCore
8
org.apache.ranger:ranger
8
github.com/cri-o/cri-o
8
opencv-contrib-python
8
org.opensearch.plugin:opensearch-security
8
parse-server
8
org.jenkins-ci.plugins:electricflow
8
camaleon_cms
8
sylius/sylius
8
neutron
8
bagisto/bagisto
8
phpbb/phpbb
8
github.com/mattermost/mattermost-plugin-confluence
8
activerecord
8
org.jenkins-ci.plugins:subversion
8
sulu/sulu
8
centreon/centreon
8
rails-html-sanitizer
8
pyload-ng
8
opencv-python
8
org.apache.archiva:archiva
8
ckan
8
onionshare-cli
8
impresscms/impresscms
8
phpmyfaq/phpmyfaq
8
modoboa
8
Filter by Repository
https://github.com/tensorflow/tensorflow
200
https://github.com/moodle/moodle
192
https://github.com/liferay/liferay-portal
140
https://github.com/jenkinsci/jenkins
109
https://github.com/pimcore/pimcore
85
https://github.com/TYPO3/typo3
64
https://github.com/apache/tomcat
63
https://github.com/microweber/microweber
63
https://github.com/silverstripe/silverstripe-framework
50
https://github.com/xwiki/xwiki-platform
50
https://github.com/usememos/memos
50
https://github.com/django/django
50
https://github.com/rails/rails
46
https://github.com/keycloak/keycloak
45
https://github.com/thorsten/phpmyfaq
45
https://github.com/apache/airflow
44
https://github.com/librenms/librenms
42
https://github.com/kubernetes/kubernetes
40
https://github.com/mattermost/mattermost
36
https://github.com/mmaitre314/picklescan
34
https://github.com/star7th/showdoc
32
https://github.com/mantisbt/mantisbt
32
https://github.com/concretecms/concretecms
28
https://github.com/symfony/symfony
27
https://github.com/grafana/grafana
27
https://github.com/mautic/mautic
27
https://github.com/ansible/ansible
26
https://github.com/spring-projects/spring-framework
26
https://github.com/craftcms/cms
26
https://github.com/phpmyadmin/phpmyadmin
26
https://github.com/directus/directus
24
https://github.com/shopware/shopware
24
https://github.com/argoproj/argo-cd
24
https://github.com/umbraco/Umbraco-CMS
23
https://github.com/Dolibarr/dolibarr
22
https://github.com/answerdev/answer
21
https://github.com/plone/Products.CMFPlone
20
https://github.com/firefly-iii/firefly-iii
20
https://github.com/apache/activemq
20
https://github.com/snipe/snipe-it
20
https://github.com/magento/magento2
20
https://github.com/cilium/cilium
19
https://github.com/livehelperchat/livehelperchat
18
https://github.com/openstack/nova
18
https://github.com/contao/contao
18
https://github.com/shopware/platform
17
https://github.com/apache/struts
17
https://github.com/matrix-org/synapse
16
https://github.com/ikus060/rdiffweb
16
https://github.com/gradio-app/gradio
16
https://github.com/netty/netty
15
https://github.com/getkirby/kirby
15
https://github.com/vyperlang/vyper
15
https://github.com/CVEProject/cvelist
15
https://github.com/apache/cxf
15
https://github.com/strapi/strapi
14
https://github.com/geoserver/geoserver
14
https://github.com/froxlor/froxlor
14
https://github.com/yetiforcecompany/yetiforcecrm
14
https://github.com/PaddlePaddle/Paddle
14
https://github.com/TYPO3/TYPO3.CMS
14
https://github.com/saltstack/salt
14
https://github.com/tinymce/tinymce
14
https://github.com/x-stream/xstream
14
https://github.com/baserproject/basercms
14
https://github.com/moby/moby
14
https://github.com/OpenNMS/opennms
14
https://github.com/octobercms/october
13
https://github.com/PrestaShop/PrestaShop
13
https://github.com/openfga/openfga
13
https://github.com/bcgit/bc-java
13
https://github.com/apache/nifi
13
https://github.com/go-gitea/gitea
13
https://github.com/rack/rack
13
https://github.com/nilsteampassnet/TeamPass
13
https://github.com/goharbor/harbor
13
https://github.com/helm/helm
12
https://github.com/hashicorp/consul
12
https://github.com/containerd/containerd
12
https://github.com/huggingface/transformers
12
https://github.com/traefik/traefik
12
https://github.com/TYPO3-CMS/core
12
https://github.com/dnnsoftware/Dnn.Platform
11
https://github.com/rancher/rancher
11
https://github.com/apache/zeppelin
11
https://github.com/OpenZeppelin/openzeppelin-contracts
11
https://github.com/openstack/keystone
11
https://github.com/ckeditor/ckeditor4
11
https://github.com/surrealdb/surrealdb
11
https://github.com/electron/electron
11
https://github.com/vaadin/platform
11
https://github.com/vitejs/vite
11
https://github.com/laravel/framework
11
https://github.com/intelliants/subrion
11
https://github.com/forkcms/forkcms
11
https://github.com/ethereum/go-ethereum
11
https://github.com/github/advisory-database
11
https://github.com/greenpau/caddy-security
10
https://github.com/bytecodealliance/wasmtime
10
https://github.com/aio-libs/aiohttp
10
https://github.com/decidim/decidim
10
https://github.com/simplesamlphp/simplesamlphp
10
https://github.com/liufee/cms
10
https://github.com/wallabag/wallabag
10
https://github.com/PHPOffice/PhpSpreadsheet
10
https://github.com/laurent22/joplin
10
https://github.com/backstage/backstage
10
https://github.com/TryGhost/Ghost
10
https://github.com/vllm-project/vllm
10
https://github.com/vercel/next.js
10
https://github.com/dotnet/runtime
9
https://github.com/fatfreecrm/fat_free_crm
9
https://github.com/opencast/opencast
9
https://github.com/puppetlabs/puppet
9
https://github.com/dpgaspar/Flask-AppBuilder
9
https://github.com/alkacon/opencms-core
9
https://github.com/thorsten/phpMyFAQ
9
https://github.com/pimcore/admin-ui-classic-bundle
9
https://github.com/urllib3/urllib3
9
https://github.com/publify/publify
9
https://github.com/jquery/jquery
9
https://github.com/jenkinsci/git-plugin
9
https://github.com/opensearch-project/security
8
https://github.com/modoboa/modoboa
8
https://github.com/rails/rails-html-sanitizer
8
https://github.com/getgrav/grav
8
https://github.com/onionshare/onionshare
8
https://github.com/OctoPrint/OctoPrint
8
https://github.com/rubygems/rubygems
8
https://github.com/sulu/sulu
8
https://github.com/zendframework/zendframework
8
https://github.com/ckan/ckan
8
https://github.com/denoland/deno
8
https://github.com/apache/superset
8
https://github.com/kubeedge/kubeedge
8
https://github.com/pandao/editor.md
8
https://github.com/pyload/pyload
8
https://github.com/gogs/gogs
8
https://github.com/eclipse/jetty.project
8
https://github.com/hashicorp/nomad
8
https://github.com/parse-community/parse-server
8
https://github.com/openbao/openbao
8
https://github.com/sparklemotion/nokogiri
8
https://github.com/swagger-api/swagger-ui
8
https://github.com/openstack/glance
8
https://github.com/nilsteampassnet/teampass
8
https://github.com/FlowiseAI/Flowise
8
https://github.com/LavaLite/cms
8
https://github.com/dolibarr/dolibarr
8
https://github.com/matrix-org/matrix-rust-sdk
7
https://github.com/chakra-core/ChakraCore
7
https://github.com/openstack/horizon
7
https://github.com/janeczku/calibre-web
7
https://github.com/n8n-io/n8n
7
https://github.com/scrapy/scrapy
7
https://github.com/vaadin/flow
7
https://github.com/dragonflyoss/dragonfly
7
https://github.com/opencontainers/runc
7
https://github.com/modxcms/revolution
7
https://github.com/MobSF/Mobile-Security-Framework-MobSF
7
https://github.com/nahsra/antisamy
7
https://github.com/zitadel/zitadel
7
https://github.com/vega/vega
7
https://github.com/undertow-io/undertow
7
https://github.com/nocodb/nocodb
7
https://github.com/croogo/croogo
7
https://github.com/python-pillow/Pillow
7
https://github.com/hashicorp/vault
7
https://github.com/Leantime/leantime
7
https://github.com/containers/podman
7
https://github.com/py-pdf/pypdf
7
https://github.com/google/fscrypt
7
https://github.com/jupyter/notebook
7
https://github.com/StarCitizenTools/mediawiki-skins-Citizen
7
https://github.com/louislam/uptime-kuma
7
https://github.com/jenkinsci/blueocean-plugin
7
https://github.com/kevinpapst/kimai2
7
https://github.com/igniterealtime/Openfire
7
https://github.com/jeecgboot/jeecg-boot
7
https://github.com/bagisto/bagisto
7
https://github.com/opencv/opencv
7
https://github.com/twbs/bootstrap
7
https://github.com/Sylius/Sylius
7
https://github.com/zenml-io/zenml
7
https://github.com/OPCFoundation/UA-.NETStandard
7
https://github.com/sfackler/rust-openssl
6
https://github.com/NodeBB/NodeBB
6
https://github.com/dompdf/dompdf
6
https://github.com/roundup-tracker/roundup
6
https://github.com/wagtail/wagtail
6
https://github.com/vantage6/vantage6
6
https://github.com/neorazorx/facturascripts
6
https://github.com/run-llama/llama_index
6
https://github.com/jenkinsci/configuration-as-code-plugin
6
https://github.com/jenkinsci/subversion-plugin
6
https://github.com/cui2shark/security
6
https://github.com/tecnickcom/TCPDF
6
https://github.com/cri-o/cri-o
6
https://github.com/oroinc/orocommerce
6