Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-33681Highwwbn/avideo: AVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin NameCVE-2026-33673Highprestashop/prestashop: PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variablesCVE-2026-33674Lowprestashop/prestashop: PrestaShop: Improper Use of Validation FrameworkCVE-2026-33661Highyansongda/pay: WeChat Pay callback signature verification bypassed when Host header is localhostCVE-2026-33651Highwwbn/avideo: AVideo has a Blind SQL Injection in Live Schedule Reminder via Unsanitized live_schedule_id in Scheduler_commands::getAllActiveOrToRepeat()CVE-2026-33650Highwwbn/avideo: AVideo: Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video DeletionCVE-2026-33649Highwwbn/avideo: AVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission ModificationCVE-2026-33648Highwwbn/avideo: AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File PathCVE-2026-33647Highwwbn/avideo: AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File UploadCVE-2026-33628Mediuminvoiceninja/invoiceninja: Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line ItemsCVE-2026-33162Mediumcraftcms/cms: Craft CMS has an authorization bypass which allows any control panel user to move entries without permissionsCVE-2026-33161Lowcraftcms/cms: Craft CMS' anonymous "assets/image-editor" calls return private asset editor metadata to unauthorized usersCVE-2026-33160Lowcraftcms/cms: Craft CMS may expose private assets through anonymous "generate transform" calls via transform URLCVE-2026-33159Mediumcraftcms/cms: Craft CMS: Unauthenticated Users Can Perform Restricted Project Config Sync OperationsCVE-2026-33158Mediumcraftcms/cms: Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)CVE-2026-33157Highcraftcms/cms: Craft CMS is Vulnerable to Authenticated Remote Code Execution via Malicious Attached BehaviorCVE-2026-30932Highfroxlor/froxlor: Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones APICVE-2026-30662Mediumconcrete5/concrete5: ConcreteCMS is vulnerable to Denial of Service During Bulk DownloadsCVE-2026-33486Mediumroadiz/documents: Roadiz has Server-Side Request Forgery (SSRF) in roadiz/documentsCVE-2026-32300Highopensource-workshop/connect-cms: Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User InformationCVE-2026-32299Highopensource-workshop/connect-cms: Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval FeatureCVE-2026-32279Mediumopensource-workshop/connect-cms: Connect CMS has SSRF in the External Page Migration Feature of its Page Management PluginCVE-2026-32278Highopensource-workshop/connect-cms: Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form PluginCVE-2026-32277Highopensource-workshop/connect-cms: Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List ViewCVE-2026-32276Highopensource-workshop/connect-cms: Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin

Stop the waste.
Protect your environment with Kodem.