Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-9G2Q-W3W2-VF7QMediumkimai/kimai: Kimai has Missing Voter Check that Allows Cross-Team Timesheet ManipulationCVE-2024-27354Highphpseclib/phpseclib: phpseclib: guardrails needed on isPrime and randomPrimeCVE-2026-44012Highcraftcms/cms: Craft CMS's Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information DisclosureCVE-2026-44011Highcraftcms/cms: Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached BehaviorCVE-2026-44010Highcraftcms/cms: Craft CMS's Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII DisclosureCVE-2026-43885Highwwbn/avideo: AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing AuthorizationCVE-2026-43884Highwwbn/avideo: AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()CVE-2026-43883Mediumwwbn/avideo: AVideo: IDOR in PayPalYPT Plugin Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription AgreementsCVE-2026-43882Mediumwwbn/avideo: AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event SpoofingCVE-2026-43881Mediumwwbn/avideo: AVideo: Unauthenticated User Enumeration in objects/users.json.php via isCompany Parameter Allows Bypass of the Admin-Only Listing…CVE-2026-43880Mediumwwbn/avideo: AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Enables Phishing from the Site’s Legitimate From AddressCVE-2026-43879Mediumwwbn/avideo: AVideo has Blind SSRF in YPTWallet Donation Webhook via Missing isSSRFSafeURL() Check and CURLOPT_FOLLOWLOCATION Redirect BypassCVE-2026-42611Highgetgrav/grav: Grav is Vulnerable to Stored XSS via Tag InjectionGHSA-3446-6MGW-F79PMediumgetgrav/grav: Grav is Vulnerable to XXE via SVG Upload CVE-2026-42608Highgetgrav/grav: Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash componentCVE-2026-42609Highgetgrav/grav: Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite LogicCVE-2026-7317Lowgetgrav/grav: Grav has Insecure Deserialization in File CacheGHSA-VJ3M-2G9H-VM4PCriticalgetgrav/grav: Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI blocklist bypassCVE-2026-42612Highgetgrav/grav: Grav Vulnerable to Publisher-Level Stored XSS via Unquoted Event AttributesCVE-2026-42610Mediumgetgrav/grav: Grav Vulnerable to Sensitive Information Disclosure via Accounts Service BypassCVE-2026-42613Criticalgetgrav/grav: Grav Vulnerable to Privilege Escalation via Missing Server-Side Validation of groups/accessCVE-2026-42842Mediumgetgrav/grav: Grav Vulnerable to XSS via Taxonomy Field Values in Admin PanelCVE-2026-42841Mediumgetgrav/grav: Grav CMS vulnerable to stored XSS via Markdown media attribute() actionCVE-2026-42607Criticalgetgrav/grav: Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install FeatureCVE-2026-42843Highgetgrav/grav-plugin-api: Grav API Privilege Escalation to Super Admin

Stop the waste.
Protect your environment with Kodem.