Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-27012Criticaldevcode-it/openstamanager: OpenSTAManager affected by unauthenticated privilege escalation via modules/utenti/actions.phpCVE-2026-26279Criticalfroxlor/froxlor: Froxlor has Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command InjectionCVE-2026-24415Mediumdevcode-it/openstamanager: OpenSTAManager Affected by XSS in modifica_iva.php via righe parameterCVE-2026-28507Highidno/known: Idno Vulnerable to Remote Code Execution via Chained Import File Write and Template Path TraversalCVE-2026-28508Criticalidno/known: Idno Vulnerable to Unauthenticated SSRF via URL Unfurl EndpointCVE-2026-28502Criticalwwbn/avideo: AVideo has Authenticated Remote Code Execution via Unsafe Plugin ZIP ExtractionCVE-2026-28501Criticalwwbn/avideo: AVideo has Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.phpCVE-2026-28426Highstatamic/cms: Statamic vulnerable to privilege escalation via stored cross-site scriptingCVE-2026-28425Highstatamic/cms: Statamic vulnerable to remote code execution via Antlers-enabled control panel inputsCVE-2026-28424Mediumstatamic/cms: Statamic's missing authorization allows access to email addressesCVE-2026-28423Mediumstatamic/cms: Statamic Vulnerable to Server-Side Request Forgery via GlideCVE-2026-27939Highstatamic/cms: Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypassCVE-2026-27836Highthorsten/phpmyfaq: phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare EndpointCVE-2026-3105Highmautic/core: Mautic is Vulnerable to SQL Injection through Contact Activity API SortingGHSA-6J87-M5QX-9FQPLowcraftcms/cms: Craft CMS has Stored XSS in Table Field in its "Row Heading" Column TypeCVE-2026-27732Highwwbn/avideo: AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.phpCVE-2026-27621Mediumtypicms/core: TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File UploadCVE-2026-27593Criticalstatamic/cms: Statamic is vulnerable to account takeover via password reset link injectionCVE-2026-27461Mediumpimcore/pimcore: Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE clauseCVE-2026-27129Mediumcraftcms/cms: Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 ResolutionCVE-2026-27128Mediumcraftcms/cms: Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limitCVE-2026-27127Highcraftcms/cms: Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS RebindingCVE-2026-27126Mediumcraftcms/cms: Craft CMS has Stored XSS in Table Field via "HTML" Column TypeCVE-2026-2897Lowfunadmin/funadmin: funadmin: XSS through Value argument in Backend Interface componentCVE-2026-2898Lowfunadmin/funadmin: funadmin: Deserialization Vulnerability in Backend Endpoint via AuthCloudService getMember Function

Stop the waste.
Protect your environment with Kodem.