Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-8409Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/deleteCVE-2026-8412Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cacheCVE-2026-8337Mediumconcrete5/concrete5: Concrete CMS is vulnerable to IDOR in surveysCVE-2026-8415Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorderCVE-2026-8245Mediumconcrete5/concrete5: Concrete CMS is Vulnerable to Reflected XSS in Legacy PaginationCVE-2026-8414Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicateCVE-2026-8411Lowconcrete5/concrete5: Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/deleteCVE-2026-8240Mediumconcrete5/concrete5: Concrete CMS is vulnerable to unauthenticated page metadata disclosureCVE-2026-8239Mediumconcrete5/concrete5: Concrete CMS is vulnerable to IDORCVE-2026-7890Lowconcrete5/concrete5: Concrete CMS's RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validationCVE-2026-8238Mediumconcrete5/concrete5: Concrete CMS is vulnerable to IDORCVE-2026-7887Lowconcrete5/concrete5: Concrete CMS: OAuth 2.0 Authorization-Code Handler Bypasses Account StatusCVE-2026-8139Lowconcrete5/concrete5: Concrete CMS is vulnerable to Stored XSS via external-link page cvNameCVE-2026-7881Mediumconcrete5/concrete5: Concrete CMS is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail blockCVE-2026-8237Mediumconcrete5/concrete5: Concrete CMS is vulnerable to IDORCVE-2026-7879Mediumconcrete5/concrete5: Concrete CMS has an unauthorized file access issueCVE-2026-8327Mediumconcrete5/concrete5: Concrete CMS has a session-hardening bypass and allows password change without reauthorizationCVE-2026-8236Mediumconcrete5/concrete5: Concrete CMS is vulnerable to IDOR combined with a missing authentication gateCVE-2026-7882Lowconcrete5/concrete5: Concrete CMS is vulnerable to unauthorized file deletionCVE-2026-7886Lowconcrete5/concrete5: Concrete CMS is vulnerable to IDOR in AddMessage/UpdateMessageCVE-2026-46640Hightwig/twig: Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilationCVE-2026-46639Hightwig/twig: Twig: Sandbox property and method bypass via object-destructuring assignmentCVE-2026-8426Highconcrete5/concrete5: Concrete CMS does not validate a CSRF token before processing requests to `/dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>`CVE-2026-8421Highconcrete5/concrete5: Concrete CMS contains a CSRF vulnerabilityCVE-2026-8428Highconcrete5/concrete5: Concrete CMS is Vulnerable to Cross-Site Request Forgery

Stop the waste.
Protect your environment with Kodem.