Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52841Lowalextselegidis/easyappointments: Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google syncCVE-2026-52837Mediumalextselegidis/easyappointments: Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule pageCVE-2026-52839Lowalextselegidis/easyappointments: Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization BypassCVE-2026-52840Lowalextselegidis/easyappointments: Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal networkCVE-2026-55651Highalextselegidis/easyappointments: Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data ExposureCVE-2026-54588Criticalpoweradmin/poweradmin: Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.CVE-2026-54593Highpterodactyl/panel: Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissionsCVE-2026-61609Highpterodactyl/panel: Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)CVE-2026-45293Highwp-coding-standards/wpcs: WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerabilityGHSA-CMWH-G2H8-C222Highpoweradmin/poweradmin: Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeoverGHSA-RM67-G9CH-VXFFHighpoweradmin/poweradmin: Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not ownGHSA-H4HF-V6W5-897XHighpoweradmin/poweradmin: Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser accountGHSA-F25V-X6VR-962GCriticalpheditor/pheditor: Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current PasswordGHSA-G3HQ-HPHG-8FHHHighpheditor/pheditor: Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization…CVE-2026-59933Highphpoffice/phpspreadsheet: PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustionCVE-2026-59932Highphpoffice/phpspreadsheet: PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustionCVE-2026-59931Highphpoffice/phpspreadsheet: PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelistCVE-2026-59943Mediumdompdf/dompdf: Dompdf: Embedded SVG images can leak existence of files and directories within the filesystemCVE-2026-59942Mediumdompdf/dompdf: Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image BitmapsCVE-2026-59941Mediumdompdf/dompdf: Dompdf: Uncontrolled resource consumption based on declared BMP dimensionsCVE-2026-56722Mediumdompdf/dompdf: Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URICVE-2026-55555Lowdompdf/dompdf: Dompdf: File existence oracle via font-face stylesheet declarationCVE-2026-55554Lowdompdf/dompdf: Dompdf: Chroot Validation BypassCVE-2026-59882Mediumguzzlehttp/psr7: guzzlehttp/psr7: Host Confusion via Weak URI Host ValidationCVE-2026-67354Mediumguzzlehttp/guzzle: Guzzle: URI fragments disclosed in redirect Referer headers

Stop the waste.
Protect your environment with Kodem.