Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45034Criticalphpoffice/phpspreadsheet: PHPSpreadsheet has a patch bypass for CVE-2026-34084 CVE-2026-47732Hightwig/twig: Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion pointsCVE-2026-47730Lowtwig/twig: Twig: XSS in profiler HtmlDumper via unescaped template and profile namesCVE-2026-24425Hightwig/twig: Twig: Possible sandbox bypass when using a source policyCVE-2026-47744Criticalshopper/framework: Shopper: Authorization bypass and RBAC privilege escalation in team settingsCVE-2026-47743Highshopper/framework: Shopper: Multiple data integrity and disclosure issues in admin Livewire componentsCVE-2026-47745Mediumshopper/framework: Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tablesCVE-2026-47742Mediumshopper/framework: Shopper: Missing authorization on Product admin Livewire sub-form componentsCVE-2026-47761Hightinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injectionCVE-2026-47762Hightinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` commentsCVE-2026-47759Hightinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributesCVE-2026-47760Hightinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGsCVE-2026-48013Mediumshopware/core: Shopware: SSRF in Media External-Link Endpoint Bypasses IP ValidationCVE-2026-48015Mediumshopware/core: Shopware: Stored XSS via SVG file upload — no SVG sanitizationCVE-2026-48016Mediumshopware/platform: Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-paymentCVE-2026-48014Mediumshopware/platform: Shopware: Admin API ACL Bypass in Order State Transition EndpointsCVE-2026-48012Mediumshopware/core: Shopware SSO referer trust leading to an arbitrary redirect targetCVE-2026-48011Lowshopware/platform: Shopware: Timing-attack on admin panel allowing enumeration of administrator usernamesCVE-2026-48010Mediumshopware/platform: Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accountsCVE-2026-48009Mediumshopware/platform: Shopware: Admin Account Takeover via User Recovery Hash ExposureCVE-2026-48008Mediumshopware/platform: Shopware: Privilege Escalation via Sync API Integration Admin Flag BypassCVE-2026-54458CriticalWWBN/AVideo: WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket PluginCVE-2026-50183MediumWWBN/AVideo: WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery SectionCVE-2026-50182MediumWWBN/AVideo: WWBN AVideo: Unauthenticated Reflected XSS via $_GET['search'] in AVideo YouTubeAPI Gallery PaginationCVE-2026-49279Highwwbn/avideo: WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)

Stop the waste.
Protect your environment with Kodem.