Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54159Criticalprestashop/ps_facetedsearch: prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCEGHSA-QV4M-M73M-8HJ7Highnotrinos/notrinos-erp: NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)CVE-2026-49865Mediumkimai/kimai: Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLsCVE-2026-49858Mediumapi-platform/core: API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gateCVE-2026-53639Mediumsylius/sylius: Sylius: IDOR on Shop Payment Request API endpointsCVE-2026-53638Mediumsylius/sylius: Sylius: Channel-based payment method restriction bypass on shop account orders API endpointCVE-2026-53637Mediumsylius/sylius: Sylius: Cart FormComponent allows modification or deletion of an already-completed orderCVE-2026-52778Criticalyeswiki/yeswiki: YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of ServiceCVE-2026-52777Criticalyeswiki/yeswiki: YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserializeCVE-2026-52775Highyeswiki/yeswiki: YesWiki has Authenticated SQL Injection via ReactionManager CVE-2026-52774Mediumyeswiki/yeswiki: YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML AttributesCVE-2026-52773Mediumyeswiki/yeswiki: YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php`CVE-2026-52772Mediumyeswiki/yeswiki: YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html'))CVE-2026-52771Highyeswiki/yeswiki: YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)CVE-2026-52770Highyeswiki/yeswiki: YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filtersCVE-2026-52769Highyeswiki/yeswiki: YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`CVE-2026-52767Highyeswiki/yeswiki: YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`CVE-2026-52766Criticalyeswiki/yeswiki: YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` actionCVE-2026-52763Mediumyeswiki/yeswiki: YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB readCVE-2026-52762Highyeswiki/yeswiki: YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic TemplatesCVE-2026-53932Highwnx/laravel-backup-restore: laravel-backup-restore has an OS Command Injection during database restoreCVE-2026-53760Mediumadmidio/admidio: Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET RequestsGHSA-86VW-X4WW-X467Highcraftcms/cms: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreviewGHSA-C43V-4CR8-6MVPLowcraftcms/cms: Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file readCVE-2026-53634Mediumcode16/sharp: Sharp Missing Authorization Check in Quick Creation Command Endpoints

Stop the waste.
Protect your environment with Kodem.