Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55578Highpheditor/pheditor: Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injectionCVE-2026-54540Highpheditor/pheditor: Pheditor has an authenticated terminal command whitelist bypassGHSA-XG43-5579-QW6VMediumadawolfa/isdoc: adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF filesCVE-2026-62944Highmantisbt/mantisbt: MantisBT: Stored XSS in print_all_bug_page_word.phpCVE-2026-52883Mediummantisbt/mantisbt: MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIsCVE-2026-52882Mediummantisbt/mantisbt: MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From UpdatersCVE-2026-52881Criticalmantisbt/mantisbt: MantisBT: Reflected XSS in admin/install.php via unescaped printf CVE-2026-52847Criticalmantisbt/mantisbt: MantisBT: Reflected XSS in admin/install.phpCVE-2026-54494Mediumphanan/koel: Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16)…CVE-2026-50552Mediumphanan/koel: Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bailCVE-2026-54491Highphanan/koel: Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch pathsGHSA-8Q6Q-M837-FV64Mediumphanan/koel: Koel has SSRF through Authenticated Subsonic podcast feed URLsCVE-2026-54493Highphanan/koel: Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio StationsCVE-2026-54492Mediumphanan/koel: Koel: Authenticated Blind SSRF via Subsonic Podcast Channel CreationCVE-2026-49280Mediummantisbt/mantisbt: MantisBT: REST API unauthorized Issue status changeCVE-2026-49273Highmantisbt/mantisbt: MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.phpCVE-2026-47156Criticalmantisbt/mantisbt: MantisBT: SOAP API Authentication Bypass with Privilege Escalation to AdministratorCVE-2026-47142Highmantisbt/mantisbt: MantisBT: SQL Injection via history_order Configuration ValueGHSA-HGJX-R89M-M7V4Criticalfacturascripts/facturascripts: FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCECVE-2026-54087Higheasycorp/easyadmin-bundle: EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageFieldCVE-2026-50157Mediumauth0/symfony: Auth0 Symfony SDK Accepted Bearer Tokens via URL Query ParameterCVE-2026-45710Lowfacturascripts/facturascripts: FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes…CVE-2026-45263Highfacturascripts/facturascripts: FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens…CVE-2026-45693Highfacturascripts/facturascripts: FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles DocumentsCVE-2026-45262Criticalfacturascripts/facturascripts: FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`

Stop the waste.
Protect your environment with Kodem.