Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-8417Highconcrete5/concrete5: Concrete does not validate a CSRF token before processing requests to `/dashboard/extend/update/do_update/<pkgHandle>`CVE-2026-8205Mediumconcrete5/concrete5: Concrete CMS is vulnerable to authorization bypass in the Calendar BlockCVE-2026-8203Highconcrete5/concrete5: Concrete CMS has Stored XSS through its height parameterCVE-2026-8350Highconcrete5/concrete5: Concrete CMS is vulnerable to missing authorization in the bulk_user_assignment.phpCVE-2026-8204Mediumconcrete5/concrete5: Concrete CMS is vulnerable to authorization bypass in the Calendar Event Frontend DialogCVE-2026-8135Highconcrete5/concrete5: Concrete CMS Vulnerable to Deserialization of Untrusted DataCVE-2026-8197Highconcrete5/concrete5: Concrete CMS is vulnerable to Stored XSS via OAuth integration nameCVE-2026-6826Mediumconcrete5/concrete5: Concrete CMS is vulnerable to unauthenticated file usage disclosureCVE-2026-8140Highconcrete5/concrete5: Concrete CMS is Vulnerable to Cross-Site Request ForgeryCVE-2026-8134Criticalconcrete5/concrete5: Concrete CMS Vulnerable to Relative Path TraversalCVE-2026-46638Mediumtwig/twig: Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)CVE-2026-46637Lowtwig/markdown-extra: Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`CVE-2026-46635Lowtwig/twig: Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)CVE-2026-46634Mediumtwig/twig: Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template nameCVE-2026-46633Criticaltwig/twig: Twig: PHP code injection via `{% use %}` template nameCVE-2026-46629Lowtwig/intl-extra: twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled argumentsCVE-2026-46628Lowtwig/twig: Twig: The `spaceless` filter implicitly marks its output as safeCVE-2026-46643HighKnpLabs/knp-snappy: Snappy: Binary path is never shell-escaped due to an inverted is_executable checkCVE-2026-46683Mediumknplabs/knp-snappy: Snappy : SSRF and local file read via the xsl-style-sheet optionCVE-2026-9082Criticaldrupal/core: Drupal Core has a SQL Injection issueCVE-2026-35675Highthorsten/phpmyfaq: phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email EnumerationCVE-2026-35672Highthorsten/phpmyfaq: phpMyFAQ: Default Empty API Token Authentication BypassCVE-2026-35671Highthorsten/phpmyfaq: phpMyFAQ: IDOR Account Takeover CVE-2026-35676Highthorsten/phpmyfaq: phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token ValidationCVE-2026-6367Mediumdrupal/core: Drupal core allows Cross-Site Scripting (XSS)

Stop the waste.
Protect your environment with Kodem.