Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-69246Highguzzlehttp/guzzle: Guzzle: Noncanonical host can bypass host-based checksCVE-2026-69245Mediumguzzlehttp/guzzle: Guzzle: Noncanonical cookie domain keeps subdomain scopeCVE-2026-54768Mediumwp-graphql/wp-graphql: WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit…CVE-2026-53599Highredaxo/source: Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php…CVE-2026-68501Mediumsylius/mollie-plugin: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PIICVE-2026-68500Highsylius/mollie-plugin: Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhookCVE-2026-52838Lowalextselegidis/easyappointments: Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSSCVE-2026-52841Lowalextselegidis/easyappointments: Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google syncCVE-2026-52837Mediumalextselegidis/easyappointments: Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule pageCVE-2026-52839Lowalextselegidis/easyappointments: Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization BypassCVE-2026-52840Lowalextselegidis/easyappointments: Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal networkCVE-2026-55651Highalextselegidis/easyappointments: Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data ExposureCVE-2026-54588Criticalpoweradmin/poweradmin: Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.CVE-2026-54593Highpterodactyl/panel: Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissionsCVE-2026-61609Highpterodactyl/panel: Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)CVE-2026-45293Highwp-coding-standards/wpcs: WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerabilityGHSA-CMWH-G2H8-C222Highpoweradmin/poweradmin: Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeoverGHSA-RM67-G9CH-VXFFHighpoweradmin/poweradmin: Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not ownGHSA-H4HF-V6W5-897XHighpoweradmin/poweradmin: Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser accountGHSA-F25V-X6VR-962GCriticalpheditor/pheditor: Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current PasswordGHSA-G3HQ-HPHG-8FHHHighpheditor/pheditor: Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization…CVE-2026-59933Highphpoffice/phpspreadsheet: PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustionCVE-2026-59932Highphpoffice/phpspreadsheet: PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustionCVE-2026-59931Highphpoffice/phpspreadsheet: PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelistCVE-2026-59943Mediumdompdf/dompdf: Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem

Stop the waste.
Protect your environment with Kodem.