Security: canyongbs/advisingapp
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Insufficient rate limiting on public submission-widget email verificationGHSA-rwc4-5vm8-5xc9 published
Aug 21, 2026 by OrrisonHigh -
Stored XSS in Customer Advisor transcript modal allows privilege escalation from unauthenticated widget user to staff/admin sessionGHSA-hpg3-vwx3-m282 published
Jun 9, 2026 by OrrisonCritical -
Permissive CORS configuration allows origin reflection with credentials on API pathsGHSA-6qqv-72w5-p2hc published
Jun 9, 2026 by OrrisonModerate
Learn more about advisories related to canyongbs/advisingapp in the GitHub Advisory Database