Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45334Mediumgetkirby/cms: Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissionsCVE-2026-45260Highpimcore/pimcore: Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handlingCVE-2026-45162Highpimcore/pimcore: Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes RestrictionCVE-2026-45065Mediumsymfony/routing: Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL InjectionCVE-2026-45063Highsymfony/security-http: Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509AuthenticatorCVE-2026-44741Highpimcore/admin-ui-classic-bundle: Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property ParameterCVE-2026-44739Highpimcore/pimcore: Pimcore Vulnerable to SQL Injection in Custom Reports Column ConfigurationCVE-2026-44177Highgetkirby/cms: Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookupCVE-2026-44176Mediumgetkirby/cms: Kirby CMS's `pages.access` permission is not checked during rendering of page draftsCVE-2026-44175Highgetkirby/cms: Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontendCVE-2026-44174Highgetkirby/cms: Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query EndpointsCVE-2026-35202Lowpterodactyl/panel: Pterodactyl has a database resource limit bypass via race condition in Client APICVE-2018-25357Criticaldolibarr/dolibarr: Dolibarr ERP CRM contains a remote code evaluation vulnerabilityCVE-2026-8340Lowconcrete5/concrete5: Concrete CMS is vulnerable to CSRF via Backend\File::approveVersionCVE-2026-8347Lowconcrete5/concrete5: Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialogCVE-2026-8353Lowconcrete5/concrete5: Concrete CMS is vulnerable to Stored XSS via page name in the Atomik themeCVE-2026-46670Criticalyeswiki/yeswiki: YesWiki: Unauthenticated SQL InjectionCVE-2026-8433Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan()CVE-2026-8432Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star()CVE-2026-8427Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)CVE-2026-8435Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()CVE-2026-8413Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/designCVE-2026-8416Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)CVE-2026-8434Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()CVE-2026-8410Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete

Stop the waste.
Protect your environment with Kodem.