Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-2896Mediumfunadmin/funadmin: funadmin has Incorrect Privilege Assignment in its Configuration HandlerCVE-2026-2894Mediumfunadmin/funadmin: funadmin exposes sensitive information via getMember functionCVE-2026-2895Lowfunadmin/funadmin: funadmin has Weak Password Recovery Mechanism for Forgotten PasswordCVE-2026-26045Highmoodle/moodle: Moodle has a Remote Code Execution risk via file restoreCVE-2026-26047Mediummoodle/moodle: Moodle TeX formula editor is vulnerable to DoS through lack of execution time limitsCVE-2026-27568Mediumwwbn/avideo: AVideo has Stored Cross-Site Scripting via Markdown Comment InjectionCVE-2026-27206Highzumba/json-serializer: Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unserialize()CVE-2026-27198Highgetformwork/formwork: Formwork Improperly Managed Privileges in User creationCVE-2026-27196Highstatamic/cms: Statamic affected by privilege escalation via stored cross-site scriptingCVE-2026-26990Highlibrenms/librenms: LibreNMS has a Time-Based Blind SQL Injection in address-search.inc.phpCVE-2026-26989Mediumlibrenms/librenms: LibreNMS has a Stored XSS in Alert RuleCVE-2026-26988Highlibrenms/librenms: LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream.CVE-2026-27016Mediumlibrenms/librenms: LibreNMS has a Stored XSS in Custom OID - unit parameter missing strip_tags()CVE-2026-26992Mediumlibrenms/librenms: LibreNMS /port-groups name Stored Cross-Site ScriptingCVE-2026-26991Mediumlibrenms/librenms: LibreNMS /device-groups name Stored Cross-Site ScriptingCVE-2026-26987Mediumlibrenms/librenms: LibreNMS affected by reflected xss via email field CVE-2026-26016Criticalpterodactyl/panel: Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing AuthorizationGHSA-HR7J-63V7-VJ7GHighpterodactyl/panel: Pterodactyl Panel's SFTP sessions remain active after user account deletion or password changeCVE-2026-2469Mediumdirectorytree/imapengine: ImapEngine affected by command injection via the ID command parametersCVE-2026-26273Criticalidno/known: Known affected by Account Takeover via Password Reset Token LeakageGHSA-R33W-FG8J-9C94Highcesargb/laravel-magiclink: MagicLink: Insecure Deserialization of MagicLink Actions Leads to Remote Code ExecutionCVE-2026-25759Highstatamic/cms: Statamic CMS vulnerable to privilege escalation via stored cross-site scriptingCVE-2026-25633Mediumstatamic/cms: Statamic CMS's missing authorization allows access to assetsCVE-2019-25317Mediumkimai/kimai: Kimai 2 vulnerable to persistent cross-site scripting in the timesheet descriptionsCVE-2018-25157Mediumphraseanet/phraseanet: Phraseanet vulnerable to stored cross-site scripting through crafted file names

Stop the waste.
Protect your environment with Kodem.