Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-33770Highwwbn/avideo: AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id VariablesCVE-2026-33767Highwwbn/avideo: AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly into QueryCVE-2026-33766Mediumwwbn/avideo: AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download EndpointsCVE-2026-33764Mediumwwbn/avideo: AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and TranscriptionsCVE-2026-33763Mediumwwbn/avideo: AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean OracleCVE-2026-33761Mediumwwbn/avideo: AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User MappingsCVE-2026-33759Mediumwwbn/avideo: AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist ContentsCVE-2026-6204Highlibrenms/librenms: LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File WriteGHSA-44PX-QJJC-XRHQLowcraftcms/cms: Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadataCVE-2026-33183Mediumsaloonphp/saloon: Saloon has a Fixture Name Path Traversal VulnerabilityCVE-2026-33182Mediumsaloonphp/saloon: Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URLCVE-2026-33723Highwwbn/avideo: AVideo is Vulnerable to SQL Injection through Subscribe Endpoint via Unsanitized user_id ParameterCVE-2026-33719Highwwbn/avideo: AVideo: Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-AssignmentCVE-2026-33717Highwwbn/avideo: AVideo: Remote Code Execution via PHP Temp File in Encoder downloadURLCVE-2026-33716Criticalwwbn/avideo: AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.phpCVE-2026-6409Highgoogle/protobuf: Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursionCVE-2026-33548Highmantisbt/mantisbt: MantisBT has Stored HTML Injection/XSS when displaying Tags in TimelineCVE-2026-33686Highcode16/sharp: Sharp is Vulnerable to Path Traversal via Unsanitized Extension in FileUtilCVE-2026-33687Highcode16/sharp: Sharp has Unrestricted File Upload via Client-Controlled Validation RulesCVE-2026-33517Highmantisbt/mantisbt: MantisBT Vulnerable to Stored HTML Injection in Tag Delete ConfirmationCVE-2026-33690Mediumwwbn/avideo: AVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()GHSA-WXJX-R2J2-96FXMediumwwbn/avideo: AVideo: Full-Read SSRF Through Unvalidated statsURL Parameter in plugin/Live/test.phpCVE-2026-33688Mediumwwbn/avideo: AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery EndpointCVE-2026-33685Mediumwwbn/avideo: AVideo Allows Unauthenticated Access to AD_Server reports.json.php that Exposes Ad Campaign Analytics and User DataCVE-2026-33683Mediumwwbn/avideo: AVideo vulnerable to Stored XSS via html_entity_decode() Reversing xss_esc() Sanitization in Channel About Field

Stop the waste.
Protect your environment with Kodem.