Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-GR3R-CRP5-QRRMCriticalintercom/intercom-php: Compromised tag of intercom-php published via GitHubCVE-2026-42845Highgetgrav/grav-plugin-form: Grav Form Plugin has an Anonymous Page Content Overwrite via Form File Upload filename OverrideCVE-2026-42552Highflightphp/core: Flight vulnerable to sensitive information disclosure via default error handlerCVE-2026-42551Highflightphp/core: Flight: HTTP method override enabled by default, facilitating CSRF escalation and middleware bypassCVE-2026-42550Highflightphp/core: Flight vulnerable to SQL Injection via unvalidated identifiers in SimplePdo::insert / update / deleteCVE-2026-42549Mediumflightphp/core: Flight has path traversal in `make:controller` CLI that creates arbitrary directories outside project rootCVE-2026-42548Highflightphp/core: Flight has reflected XSS through an unvalidated JSONP callback in Flight::jsonp() CVE-2026-42844Highgetgrav/grav: Low-privileged Grav API users can create super-admin accounts via blueprint-uploadCVE-2026-42458Mediumopenmage/magento-lts: Magento LTS: Reflected XSS - Import -> Data Flow (profiles) CVE-2026-44306Mediumstatamic/cms: Statamic CMS vulnerable to email enumeration via forgot password endpointCVE-2026-46364Criticalthorsten/phpmyfaq: phpMyFAQ has unauthenticated SQL injection via User-Agent header in BuiltinCaptchaCVE-2026-45008Mediumthorsten/phpmyfaq: phpMyFAQ: Path Traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin adminsCVE-2026-46366Highthorsten/phpmyfaq: phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback queryCVE-2026-46359Highthorsten/phpmyfaq: phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fieldsCVE-2026-45010Criticalthorsten/phpmyfaq: phpMyFAQ enables unauthenticated 2FA brute-force attack via /admin/check acceptance of arbitrary user-idCVE-2026-45009Mediumthorsten/phpmyfaq: phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check in phpMyFAQCVE-2026-46361Mediumphpmyfaq/phpmyfaq: phpMyFAQ has stored XSS via | raw Filter in search.twig — html_entity_decode(strip_tags()) Bypass in Search Result RenderingCVE-2026-45007Mediumthorsten/phpmyfaq: phpMyFAQ's Missing CONFIGURATION_EDIT Permission Check on 12 Admin API Configuration Tab Endpoints Allows Information Disclosure by Any…CVE-2026-46360Mediumphpmyfaq/phpmyfaq: phpMyFAQ has a SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSSCVE-2026-46363Mediumphpmyfaq/phpmyfaq: phpMyFAQ has Stored XSS in FAQ Question/Answer via Encode-Decode Bypass of removeAttributes() SanitizationGHSA-7CX3-2QX2-3G6WMediumphpmyfaq/phpmyfaq: phpMyFAQ's Missing Authorization on Tag Deletion Allows Any Authenticated User to Delete TagsCVE-2026-46362Mediumphpmyfaq/phpmyfaq: phpMyFAQ has an Authorization Bypass in All Admin Pages Due to Non-Terminating Permission CheckCVE-2026-46367Highthorsten/phpmyfaq: phpMyFAQ has stored XSS via Utils::parseUrl() in comment renderingCVE-2026-44262Criticaldedoc/scramble: Scramble vulnerable to remote code execution via evaluation of user-controlled input in validation rulesGHSA-VRQV-52X7-RM4VMediumkimai/kimai: Kimai's Twig function config() leaks server-wide secrets (LDAP bind password, SAML SP private key) via invoice/export templates

Stop the waste.
Protect your environment with Kodem.