Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-61449Mediumgetgrav/grav: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/InstallerCVE-2026-58657Mediumgetgrav/grav: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in GravCVE-2026-61453Mediumgetgrav/grav: Grav: XSS Blueprint Validation Bypass via Twig String ConcatenationCVE-2026-59193Mediumgetgrav/grav: Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()GHSA-2XMM-M4WV-3FJHLowoctober/october: October CMS: Incomplete Scheme Validation in Image ResizerCVE-2026-49400Lowoctober/system: October CMS: PHP Object Injection via Backend Widget Session StorageCVE-2026-46696Lowoctober/system: October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder CallsCVE-2026-56825Highshopper/framework: Shopper: Missing authorization on product removal actions in CollectionProducts componentCVE-2026-56830Mediumshopper/framework: Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)CVE-2026-56829Highshopper/framework: Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock componentCVE-2026-56828Highshopper/framework: Shopper: privilege escalation via improper Livewire admin component authorizationCVE-2026-56826Mediumshopper/framework: Shopping privilege escalation through missing authorization in Settings componentsCVE-2026-56831Mediumshopper/framework: Shopper: Negative discount values accepted and propagated through order calculation pipelineCVE-2026-56827Highshopper/framework: Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility…CVE-2026-55416Highpimcore/pimcore: Pimcore: SQL Injection in Custom Reports via Malicious Report ConfigurationCVE-2026-81525Highmongodb/mongodb: mongodb: Reject "." and NUL bytes in database and collection namesCVE-2026-84361Highcomposer/composer: Composer arbitrary command execution via a malicious package's Perforce source URLCVE-2026-84308Mediumphpseclib: phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recoveryCVE-2026-84372Criticalpredis/predis: Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionsCVE-2026-77635Criticalcakephp/cakephp: CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriverCVE-2026-77634Highcakephp/cakephp: CakePHP: SmtpTransport vulnerable to CRLF header injectionCVE-2026-84374Highmaatwebsite/excel: Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled pathCVE-2026-62669Highgetgrav/grav: Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending ChallengeCVE-2026-61842Mediumgetgrav/grav: Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)CVE-2026-61690Mediumgetgrav/grav: Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits

Stop the waste.
Protect your environment with Kodem.