Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40909Highwwbn/avideo: WWBN AVideo has a Path Traversal in Locale Save Endpoint Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)CVE-2026-40908Mediumwwbn/avideo: WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php Exposes Developer Emails and Deployed VersionCVE-2026-40907Mediumwwbn/avideo: WWBN AVideo has an IDOR in Live Restreams list.json.php Exposes Other Users' Stream Keys and OAuth TokensCVE-2026-39971Highs9y/serendipity: Serendipity has a Host Header Injection allows SMTP header injection via unvalidated HTTP_HOST in Message-ID email headerCVE-2026-39963Mediums9y/serendipity: Serendipity has a Host Header Injection allows authentication cookie scoping to attacker-controlled domain in functions_config.inc.phpCVE-2026-25133Mediumoctober/rain: October Rain has Stored XSS via SVG Filter BypassCVE-2026-25125Mediumoctober/rain: October Rain has Environment Variable Exfiltration via INI Parser InterpolationCVE-2026-40176Highcomposer/composer: Composer has a command injection via malicious perforce repositoryCVE-2026-24907Mediumoctober/system: October CMS has Stored XSS in Event Log Mail PreviewCVE-2026-24906Mediumoctober/system: October CMS has Stored XSS in Backend Editor Markup ClassesCVE-2026-22692Mediumoctober/rain: October Rain has a Twig Sandbox Bypass via Collection MethodsCVE-2026-40261Highcomposer/composer: Composer has a command injection via malicious perforce referenceCVE-2026-38527Highkrayin/laravel-crm: Webkul Krayin CRM has Server-Side Request Forgery (SSRF)CVE-2026-38530Highkrayin/laravel-crm: Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.phpCVE-2026-38532Highkrayin/laravel-crm: Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.phpCVE-2026-38529Highkrayin/laravel-crm: Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.phpGHSA-RH42-6RJ2-XWMCLowkimai/kimai: Kimai leaks API Token Hash via Invoice Twig TemplateGHSA-3JP4-MHH4-GCGRLowkimai/kimai: Kimai has an Open Redirect via Unvalidated RelayState in SAML ACS HandlerCVE-2026-40476Mediumwebonyx/graphql-php: graphql-php is affected by a Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validationCVE-2026-32270Lowcraftcms/commerce: Craft Commerce has an unauthenticated information disclosure that can leak some customer order data on anonymous paymentsCVE-2026-32271Highcraftcms/commerce: Craft Commerce has a SQL Injection can lead to Remote Code Execution via TotalRevenue WidgetCVE-2026-32272Highcraftcms/commerce: Craft Commerce hasVariant/hasProduct Blind SQL InjectionCVE-2019-25710Highdolibarr/dolibarr: Dolibarr has SQL injection vulnerability in the rowid parameter of the admin dict.phpCVE-2026-40301Mediumrhukster/dom-sanitizer: rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directivesCVE-2026-40194Lowphpseclib/phpseclib: phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()

Stop the waste.
Protect your environment with Kodem.