Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-XQ4J-G85Q-WF97Lowredaxo/source: REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)GHSA-M662-8JRJ-CW6VLowredaxo/source: REDAXO has reflected XSS in backend Metainfo API via type parameter (CSRF token required)CVE-2026-39976Highlaravel/passport: Laravel Passport: TokenGuard Authenticates Unrelated User for Client Credentials TokensCVE-2026-39394Highci4-cms-erp/ci4ms: CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install ControllerCVE-2026-39393Highci4-cms-erp/ci4ms: CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard BypassCVE-2026-39392Mediumci4-cms-erp/ci4ms: CI4MS has stored XSS in Pages Content Due to Missing html_purify SanitizationCVE-2026-39391Mediumci4-cms-erp/ci4ms: CI4MS has stored XSS via Unescaped Blacklist Note in Admin User ListCVE-2026-39390Mediumci4-cms-erp/ci4ms: CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe settingCVE-2026-39389Mediumci4-cms-erp/ci4ms: CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected FilesCVE-2026-39370HighWWBN/AVideo: WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete…CVE-2026-39369HighWWBN/AVideo: WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLsCVE-2026-39368MediumWWBN/AVideo: WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal servicesCVE-2026-39367Mediumwwbn/avideo: WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG PageCVE-2026-39366Mediumwwbn/avideo: WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.phpCVE-2025-70844Mediumkantorge/yaffa: yaffa vulnerable to Cross Site ScriptingGHSA-F9JP-856V-8642Lowpocketmine/pocketmine-mp: PocketMine-MP: Player entities can still die and drop items in flaggedForDespawn stateGHSA-7HMV-4J2J-PP6FMediumpocketmine/pocketmine-mp: PocketMine-MP: Network amplification vulnerability with `ActorEventPacket`GHSA-788V-5PFP-93FFHighpocketmine/pocketmine-mp: PocketMine-MP: JSON decoding of unlimited size large arrays/objects in ModalFormResponse HandlingGHSA-H6RJ-3M53-887HHighpocketmine/pocketmine-mp: PocketMine-MP: LogDoS by large complex unknown property logging in clientData in LoginPacketCVE-2026-31313Mediumfeehi/cms: Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing moduleCVE-2026-31353Mediumfeehi/cms: Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Category moduleCVE-2026-31354Mediumfeehi/cms: Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions moduleCVE-2026-31352Mediumfeehi/cms: Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Role Management moduleCVE-2026-31351Mediumfeehi/cms: Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing moduleCVE-2026-31350Mediumfeehi/cms: Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Page Sign parameter

Stop the waste.
Protect your environment with Kodem.