Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45620MediumWWBN/AVideo: AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives…CVE-2026-45619MediumWWBN/AVideo: AVideo CVE-2026-43884 incomplete fix - six (or more) `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD…CVE-2026-45610MediumWWBN/AVideo: AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FACVE-2026-45580MediumWWBN/AVideo: AVideo: stored XSS via unescaped stream key in modeYoutubeLive.php class attributeCVE-2026-45578HighWWBN/AVideo: AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URLCVE-2026-23695Mediumcockpit-hq/cockpit: Cockpit CMS: Stored cross-site scripting vulnerability in the Set field type's Display template optionGHSA-QXVM-R42F-5P8JHighWWBN/AVideo: AVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`,…CVE-2026-46491Highsimplesamlphp/simplesamlphp-module-casserver: SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletionCVE-2026-44692Highcode16/sharp: Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpointCVE-2026-41147Highnukeviet/nukeviet: NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request classCVE-2025-65954Mediumsimplesamlphp/simplesamlphp-module-casserver: SimpleSAMLphp casserver: Open Redirect in logoutCVE-2026-41249Highcoreshop/core-shop: CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` ConfigurationCVE-2026-44738Highgetgrav/grav: Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()CVE-2026-44657Highmantisbt/mantisbt: MantisBT Vulnerable to Stored XSS in File DownloadCVE-2026-44655Highmantisbt/mantisbt: MantisBT has Stored XSS on Move Attachments Admin PageCVE-2026-42071Highmantisbt/mantisbt: MantisBT has a Private Bugnote Attachment Content Leak via REST APICVE-2026-42070Mediummantisbt/mantisbt: MantisBT: Authorization Bypass in Bugnote Editing via Issue Update APICVE-2026-41897Mediummantisbt/mantisbt: MantisBT is Vulnerable to Reflected XSS in Rendering Dynamic Custom Textarea FieldCVE-2026-40607Highmantisbt/mantisbt: MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner ColumnCVE-2026-40598Mediummantisbt/mantisbt: MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update PageCVE-2026-40597Highmantisbt/mantisbt: MantisBT has a Content Security Policy bypass via attachmentsCVE-2026-40596Highmantisbt/mantisbt: MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preferenceCVE-2026-39960Mediummantisbt/mantisbt: MantisBT is Vulnerable to Stored XSS in Custom Field Textarea ValuesCVE-2026-39850Highyiisoft/yii2: Yii 2: Local file inclusion via view parameter name collisionCVE-2026-34970Mediummantisbt/mantisbt: MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked

Stop the waste.
Protect your environment with Kodem.