Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-F5WM-88JV-G5HXHighcraftcms/cms: Craft CMS: Authenticated RCE through Twig sandbox escapeCVE-2026-14793Mediumcraftcms/cms: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global SetsGHSA-265M-7826-WJQMHighcraftcms/cms: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypassGHSA-MJ63-M3RC-8PPRMediumleague/commonmark: league/commonmark: Denial of service via deeply nested XML outputGHSA-MH25-X5HQ-WRQPHighleague/commonmark: league/commonmark: Denial of service via colliding heading slugsGHSA-JFM3-95JQ-Q3RFHighleague/commonmark: league/commonmark: Denial of service via duplicate footnote definitionsGHSA-G2GP-3WWQ-F4PHHighleague/commonmark: league/commonmark: Denial of service via adjacent inline attribute blocksCVE-2026-71488Highleague/commonmark: league/commonmark: Quadratic-time denial of service when parsing crafted MarkdownCVE-2026-71478Mediumleague/commonmark: league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytesCVE-2026-54717Mediumsilverstripe/cms: Silverstripe: XSS in breadcrumbs in page list viewCVE-2026-55825Lowcontao/contao: Contao: Possible path traversal in job download URIsCVE-2026-55824Lowcontao/contao: Contao crawler leaks auth credentials to external hostsCVE-2026-71435Mediumstatamic/cms: Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email TemplateCVE-2026-71434Mediumstatamic/cms: Statamic: Missing file upload validation on frontend forms allows uploading disallowed file typesCVE-2026-64662Mediumstatamic/cms: Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entriesCVE-2026-64663Mediumstatamic/cms: Statamic: Unsafe method invocation via Antlers template resolution allows data destructionCVE-2026-64665Highstatamic/cms: Statamic: Account takeover via OAuth email matching without email-verification checkCVE-2026-64664Mediumstatamic/cms: Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existenceCVE-2026-69246Highguzzlehttp/guzzle: Guzzle: Noncanonical host can bypass host-based checksCVE-2026-69245Mediumguzzlehttp/guzzle: Guzzle: Noncanonical cookie domain keeps subdomain scopeCVE-2026-54768Mediumwp-graphql/wp-graphql: WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit…CVE-2026-53599Highredaxo/source: Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php…CVE-2026-68501Mediumsylius/mollie-plugin: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PIICVE-2026-68500Highsylius/mollie-plugin: Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhookCVE-2026-52838Lowalextselegidis/easyappointments: Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS

Stop the waste.
Protect your environment with Kodem.