Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40902Highphpoffice/phpspreadsheet: PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row DimensionsCVE-2026-40863Highphpoffice/phpspreadsheet: PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML ReaderCVE-2026-34084Criticalphpoffice/phpspreadsheet: PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlledCVE-2026-38993Mediumcockpit-hq/cockpit: Cockpit is vulnerable to directory traversalCVE-2026-38991Highcockpit-hq/cockpit: Cockpit Vulnerable to Unrestricted Upload of File with Dangerous TypeCVE-2026-38992Criticalcockpit-hq/cockpit: Cockpit is vulnerable to arbitrary code executionCVE-2026-40296Mediumphpoffice/phpspreadsheet: PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writerCVE-2026-35453Mediumphpoffice/phpspreadsheet: PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML WriterCVE-2026-32699Mediumfacturascripts/facturascripts: FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' FieldCVE-2026-5362Mediumpimcore/pimcore: Pimcore has an authenticated Cross-site Scripting issueCVE-2026-6982Mediumshowdoc/showdoc: ShowDoc has an Injection vulnerabilityCVE-2026-41325Highgetkirby/cms: Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injectionCVE-2026-6553Hightypo3/cms-backend: TYPO3 CMS Stores Cleartext Password in User Settings ModuleCVE-2026-41498Lowkimai/kimai: Kimai has Missing Object-Level Authorization in the Team APICVE-2026-42202Mediumalmirhodzic/nova-toggle-5: nova-toggle-5: Improper authorization on toggle endpoint allowed non-Nova users to modify boolean fieldsCVE-2026-40099Mediumgetkirby/cms: Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameterCVE-2026-34587Highgetkirby/cms: Kirby has Server-Side Template Injection (SSTI) via double template resolution in option renderingCVE-2026-32870Mediumgetkirby/cms: Kirby has XML injection in its XML creator toolkitCVE-2026-41887Mediumflarum/core: Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)CVE-2026-41203Criticalci4-cms-erp/ci4ms: CI4MS Theme::upload is vulnerable to Zip Slip leading to RCECVE-2026-41202Criticalci4-cms-erp/ci4ms: CI4MS Backup::restore is vulnerable to Zip Slip leading to RCECVE-2026-41201Mediumci4-cms-erp/ci4ms: CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSSGHSA-MH6W-VXFF-9WQPHighphpunit/phpunit: PHPUnit: Argument injection via newline in PHP INI values forwarded to child processesCVE-2026-6744Lowbagisto/bagisto: Bagisto affected by Server-Side Request ForgeryCVE-2026-6745Lowbagisto/bagisto: Bagisto affected by Cross-site Scripting

Stop the waste.
Protect your environment with Kodem.