Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-23476Mediumfacturascripts/facturascripts: FacturaScripts is Vulnerable to Reflected XSSCVE-2026-24788Highbillz/raspap-webgui: RaspAP raspap-webgui contains an OS Command Injection vulnerabilityCVE-2026-25129Mediumpsy/psysh: PsySH has Local Privilege Escalation via CWD .psysh.php auto-loadCVE-2026-24739Mediumsymfony/process: Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on WindowsCVE-2026-22243Highegroupware/egroupware: EGroupware has SQL Injection in Nextmatch Filter ProcessingCVE-2026-24765Highphpunit/phpunit: PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage HandlingCVE-2020-36947Highlibrenms/librenms: LibreNMS contains an authenticated SQL Injection vulnerabilityCVE-2026-24422Mediumphpmyfaq/phpmyfaq: phpMyFAQ: Public API endpoints expose emails and invisible questionsCVE-2026-24421Mediumphpmyfaq/phpmyfaq: phpMyFAQ: /api/setup/backup accessible to any authenticated user (authz missing)CVE-2026-24420Mediumphpmyfaq/phpmyfaq: phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)CVE-2025-71177Mediumlavalite/cms: LavaLite CMS affected by a stored cross-site scripting vulnerabilityCVE-2025-67847Highmoodle/moodle: Moodle affected by a code injection vulnerabilityCVE-2026-26188Lowsolspace/craft-freeform: Freeform Craft Plugin CP UI (builder/integrations) has Stored Cross-Site Scripting (XSS) issueCVE-2021-47853Highphppgadmin/phppgadmin: phpPgAdmin contains a remote command execution vulnerabilityCVE-2026-23959Mediumcoreshop/core-shop: CoreShop Vulnerable to SQL Injection via Admin customer-company-modifierCVE-2026-0895Mediumcpsit/typo3-mailqueue: mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransportCVE-2026-23524Criticallaravel/reverb: Laravel Redis Horizontal Scaling Insecure DeserializationCVE-2026-23626Mediumkimai/kimai: Kimai has an Authenticated Server-Side Template Injection (SSTI)CVE-2025-69198Mediumpterodactyl/panel: Pterodactyl improperly locks resources allowing raced queries to create more resources than allotedCVE-2026-1196Lowmineadmin/mineadmin: MineAdmin May Expose Sensitive Information to an Unauthorized ActorCVE-2026-1195Lowmineadmin/mineadmin: MineAdmin improperly refreshes tokensCVE-2026-1194Mediummineadmin/mineadmin: MineAdmin May Expose Sensitive Information to an Unauthorized ActorCVE-2026-1193Lowmineadmin/mineadmin: MineAdmin has Incorrect Privilege AssignmentCVE-2026-23643Mediumcakephp/cakephp: CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scriptingCVE-2025-14894Highlivewire-filemanager/filemanager: Livewire Filemanager does not restrict uploaded file types

Stop the waste.
Protect your environment with Kodem.