Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-8GRV-JQ2G-CFHWMediumamphp/http-server: amphp/http-server affected by HTTP/2 DDoS vulnerabilityCVE-2026-25892Highvrana/adminer: Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version EndpointCVE-2026-25878Mediumfrosh/adminer-platform: FroshAdminer Adminer UI is accessible without admin sessionCVE-2026-25498Highcraftcms/cms: Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached BehaviorCVE-2026-25497Highcraftcms/cms: Craft CMS: GraphQL Asset Mutation Privilege EscalationCVE-2026-25496Mediumcraftcms/cms: Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix FieldsCVE-2026-25495Highcraftcms/cms: Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`CVE-2026-25494Mediumcraftcms/cms: Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP NotationCVE-2026-25493Mediumcraftcms/cms: Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP RedirectCVE-2026-25492Mediumcraftcms/craft: Craft CMS: save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying hostCVE-2026-25491Lowcraftcms/cms: Craft CMS Vulnerable to Stored XSS in Entry Types NameCVE-2026-24419Highdevcode-it/openstamanager: OpenSTAManager has a SQL Injection in the Prima Nota module CVE-2026-24418Highdevcode-it/openstamanager: OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations moduleCVE-2026-24417Highdevcode-it/openstamanager: OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of ServiceCVE-2026-24416Highdevcode-it/openstamanager: OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing ModuleCVE-2025-69216Highdevcode-it/openstamanager: OpenSTAManager has a SQL Injection in Scadenzario Print TemplateCVE-2025-69214Highdevcode-it/openstamanager: OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)CVE-2025-69212Criticaldevcode-it/openstamanager: OpenSTAManager has an OS Command Injection in P7M File ProcessingCVE-2025-70791Lowmicroweber/microweber: Microweber has a Cross-site Scripting vulnerabilityCVE-2025-70792Lowmicroweber/microweber: Microweber Cross-site Scripting vulnerabilityCVE-2026-22254Lowwinter/wn-cms-module: Winter CMS has Stored Cross-site Scripting (XSS) in Asset ManagerCVE-2026-25597Mediumprestashop/prestashop: PrestaShop affected by time based enumeration in FO login formCVE-2025-69215Highdevcode-it/openstamanager: OpenSTAManager has an SQL Injection in the Stampe ModuleCVE-2025-69213Highdevcode-it/openstamanager: OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)CVE-2026-25514Highfacturascripts/facturascripts: FacturaScripts has SQL Injection in Autocomplete Actions

Stop the waste.
Protect your environment with Kodem.