Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-6366Mediumdrupal/core: Drupal core allows Object InjectionCVE-2026-6365Mediumdrupal/core: Drupal core is Vulnerable to Cross-Site ScriptingCVE-2026-45802Mediumsetasign/fpdi: FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of ServiceCVE-2026-31069Highbillabear/billabear: BillaBear is Vulnerable to SQL Injection in the EventRepositoryCVE-2026-46337MediumWWBN/AVideo: AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`CVE-2026-45793Highcomposer/composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logsCVE-2026-8727Hightomasnorre/crawler: TYPO3 Remote Code Execution in extension "Site Crawler" (crawler)CVE-2026-8726Highgeorgringer/news: georgringer/news has SQL Injection in extension "News system" (news)CVE-2026-46721Mediumevoweb/sf-register: TYPO3 sf_register extension allows unauthorized assignment of frontend user groupsCVE-2026-8827Highfriendsoftypo3/tt-address: TYPO3 SQL Injection in extension "Address List" (tt_address)CVE-2026-46725Criticalmmc/ceselector: TYPO3 Remote Code Execution in extension "Content Element Selector" (ceselector)CVE-2026-46724Mediumtpwd/ke_search: TYPO3 ke_search path traversal due to lack of normalization on config directory from file indexerCVE-2026-46722Mediumtpwd/ke_search: TYPO3 ke_search XML External Entity InjectionCVE-2026-46723Mediumtpwd/ke_search: TYPO3 ke_search path traversal from arbitrary table configuration inputCVE-2026-45731MediumWWBN/AVideo: AVideo: Authenticated Arbitrary File Read in view/update.phpGHSA-9M6V-8FXC-4R44Lowsulu/sulu: Sulu: Used API Keys may be available via Admin APICVE-2026-45701Mediumsulu/sulu: Sulu: Weak Cryptographical usage for API Key generation and Reset TokensCVE-2026-45697Criticalverbb/formie: Formie: Pre-authenticated server-side template injection in Hidden fieldsCVE-2026-2728Lowlibrenms/librenms: LibreNMS: Cross-Site Scripting in ShowConfigControllerCVE-2026-47741Mediumshopper/cart: shopper/framework: Race condition on Discount.usage_limit allows silent over-redemptionCVE-2026-47740Highshopper/framework: shopper/framework: Authorization bypass in multiple Livewire admin componentsCVE-2026-45270Highci4-cms-erp/ci4ms: CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation RuleCVE-2026-45139Mediumci4-cms-erp/ci4ms: CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operationsCVE-2026-45138Mediumci4-cms-erp/ci4ms: CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation RuleCVE-2026-45660Mediumstatamic/cms: Statamic CMS: Server-Side Request Forgery via Glide

Stop the waste.
Protect your environment with Kodem.