Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-RWR8-XRPW-9QF5Lowsolspace/craft-freeform: solspace/craft-freeform Exposed to Known Axios Vulnerabilities via Precompiled AssetsGHSA-44JG-MV3H-WJ6GLowsolspace/craft-freeform: solspace/craft-freeform Vulnerable to XSS in `PhpSpreadsheet` HTML Writer Due to Unsanitized Styling DataGHSA-58Q2-9X27-H2JMLowsolspace/craft-freeform: solspace/craft-freeform Has a DoS VulnerabilityCVE-2026-23622Highalextselegidis/easyappointments: alextselegidis/easyappointments is Vulnerable to CSRF Protection BypassCVE-2021-47763Highaimeos/aimeos-laravel: Aimeos contains a SQL injection vulnerability in the json api 'sort' parameterCVE-2026-23496Mediumpimcore/web2print-tools-bundle: Pimcore Web2Print Tools Bundle "Favourite Output Channel Configuration" Missing Function Level AuthorizationCVE-2026-23495Mediumpimcore/admin-ui-classic-bundle: Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" ListingCVE-2026-23494Mediumpimcore/pimcore: Pimcore is Vulnerable to Broken Access Control: Missing Function Level Authorization on "Static Routes" ListingCVE-2026-23493Highpimcore/pimcore: Pimcore ENV Variables and Cookie Informations are exposed in http_error_logGHSA-595P-G7XC-C333Mediumalgolia/algoliasearch-magento-2: Algolia Search & Discovery for Magento 2 Has Untrusted Data HandlingCVE-2026-23492Highpimcore/pimcore: Pimcore Has an Incomplete Patch for CVE-2023-30848CVE-2025-63644Mediumph7software/ph7builder: pH7-Social-Dating-CMS affected by a stored cross-site scripting (XSS) vulnerabilityCVE-2026-23498Highshopware/shopware: Shopware Has Improper Control of Generation of Code in Twig rendered viewsCVE-2022-50807Mediumconcrete5/concrete5: Concrete5 CMS contains an XPath injection vulnerabilityCVE-2026-0859Mediumtypo3/cms-core: TYPO3 CMS Allows Insecure Deserialization via Mailer File SpoolCVE-2025-59022Hightypo3/cms-recycler: TYPO3 CMS Allows Broken Access Control in Recycler ModuleCVE-2025-59021Mediumtypo3/cms-redirects: TYPO3 CMS Allows Broken Access Control in Redirects ModuleCVE-2025-59020Mediumtypo3/cms-backend: TYPO3 CMS Allows Broken Access Control in Edit Document ControllerCVE-2025-61676Mediumoctober/system: October CMS Vulnerable to Stored XSS via Branding StylesCVE-2025-61674Mediumoctober/system: October CMS Vulnerable to Stored XSS via Editor and Branding StylesCVE-2026-21896Mediumgetkirby/cms: Kirby is missing permission checks in the content changes APICVE-2026-22242Mediumcoreshop/core-shop: CoreShop Vulnerable to SQL Injection via Admin ReportsCVE-2025-69197Mediumpterodactyl/panel: Pterodactyl TOTPs can be reused during validity windowCVE-2025-68954Highpterodactyl/panel: Pterodactyl does not revoke SFTP access when server is deleted or permissions reducedCVE-2026-21857Highredaxo/source: Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read

Stop the waste.
Protect your environment with Kodem.