Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52828Mediumkimai/kimai: Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD AccessCVE-2026-52827Highkimai/kimai: Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTPCVE-2026-52826Mediumkimai/kimai: Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate ManipulationCVE-2026-52825Mediumkimai/kimai: Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized…CVE-2026-52824Criticalkimai/kimai: Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account TakeoverCVE-2026-52823Mediumkimai/kimai: Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State ChangesCVE-2026-52822Mediumkimai/kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access RevocationCVE-2026-52821Mediumkimai/kimai: Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized ProjectsCVE-2026-52820Mediumkimai/kimai: Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypassCVE-2026-52819Mediumkimai/kimai: Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the…CVE-2026-49992Mediumkimai/kimai: Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure ChangesCVE-2026-47677Criticalfacturascripts/facturascripts: FacturaScripts: Account takeover of any 2FA-enabled userCVE-2026-55372Highnukeviet/nukeviet: NukeViet: Pre-authentication SSRF via X-Forwarded-HostCVE-2026-54065Highnukeviet/nukeviet: NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment FunctionCVE-2026-54064Highnukeviet/nukeviet: NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News ModuleCVE-2026-49259Highnukeviet/nukeviet: NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CVE-2026-48118Highnukeviet/nukeviet: NukeViet: Unauthenticated Reflected XSS in Comment ModuleCVE-2026-54159Criticalprestashop/ps_facetedsearch: prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCEGHSA-QV4M-M73M-8HJ7Highnotrinos/notrinos-erp: NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)CVE-2026-49865Mediumkimai/kimai: Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLsCVE-2026-49858Mediumapi-platform/core: API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gateCVE-2026-53639Mediumsylius/sylius: Sylius: IDOR on Shop Payment Request API endpointsCVE-2026-53638Mediumsylius/sylius: Sylius: Channel-based payment method restriction bypass on shop account orders API endpointCVE-2026-53637Mediumsylius/sylius: Sylius: Cart FormComponent allows modification or deletion of an already-completed orderCVE-2026-52778Criticalyeswiki/yeswiki: YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

Stop the waste.
Protect your environment with Kodem.