Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-68455Highcraftcms/cms: Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached BehaviorCVE-2025-68456Highcraftcms/cms: Unauthenticated Craft CMS users can trigger a database backupCVE-2025-68454Mediumcraftcms/cms: Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTICVE-2025-68437Mediumcraftcms/cms: Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload MutationCVE-2025-68436Mediumcraftcms/cms: Craft CMS vulnerable to potential information disclosure via unchecked asset relocationCVE-2026-21449Highbagisto/bagisto: Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege usersCVE-2026-21447Highbagisto/bagisto: Bagisto has IDOR in Customer Order Reorder FunctionalityCVE-2026-21448Highbagisto/bagisto: Bagisto has Normal & Blind SSTI from low-privilege user when ordering productCVE-2026-21450Highbagisto/bagisto: Bagisto SSTI vulnerability in type parameter can lead to RCECVE-2026-21451Mediumbagisto/bagisto: Bagisto has HTML Filter Bypass that Enables Stored XSSCVE-2026-21446Highbagisto/bagisto: Bagisto Missing Authentication on Installer API EndpointsCVE-2025-69277Mediumparagonie/sodium_compat: libsodium has Incomplete List of Disallowed InputsCVE-2025-69210Highfacturascripts/facturascripts: FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File UploadGHSA-6MP4-Q625-MXJPHighyourls/yourls: YOURLS is vulnerable to XSS through JSONP and Callback request parametersCVE-2025-67746Lowcomposer/composer: Composer is vulnerable to ANSI sequence injectionCVE-2025-69200Highthorsten/phpmyfaq: phpMyFAQ has unauthenticated config backup download via /api/setup/backupGHSA-MGR9-6C2J-JXRQLowpterodactyl/panel: Pterodactyl has a Reflected XSS vulnerability in “Create New Database Host”CVE-2025-68951Mediumthorsten/phpmyfaq: phpMyFAQ has Stored XSS in user list via admin-managed display_nameCVE-2024-42718Highcroogo/croogo: Croogo CMS has a path traversal vulnerabilityCVE-2025-51511Highcadmium-org/cadmium-cms: Cadmium CMS has a background arbitrary file upload vulnerabilityCVE-2025-68614Mediumlibrenms/librenms: LibreNMS Alert Rule API Cross-Site Scripting VulnerabilityCVE-2023-53957Highkimai/kimai: Kimai contains a SameSite cookie vulnerabilityCVE-2025-14761Mediumaws/aws-sdk-php: AWS SDK for PHP's S3 Encryption Client has a Key Commitment IssueCVE-2023-53929Mediumthorsten/phpmyfaq: phpMyFAQ contains a CSV injection vulnerabilityGHSA-VVG7-8RMQ-92G7Mediumauth0/wordpress: Auth0 WordPress has Improper Audience Validation via Auth0-PHP SDK Dependency

Stop the waste.
Protect your environment with Kodem.