Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-F3R2-88MQ-9V4GMediumauth0/symfony: Auth0 Symfony SDK has Improper Audience Validation via Auth0-PHP SDKGHSA-7HH9-GP72-WH7HMediumauth0/login: Auth0 Laravel SDK has Improper Audience Validation via Auth0-PHP SDK dependencyCVE-2025-68129Mediumauth0/auth0-php: Auth0-PHP SDK has Improper Audience ValidationCVE-2025-67165Criticalpagekit/pagekit: Pagekit CMS has an Insecure Direct Object Reference (IDOR) in its User Role componentCVE-2025-67164Criticalpagekit/pagekit: Pagekit CMS is vulnerable to OS Command Injection via Storage componentCVE-2025-68113Mediumaltcha-lib: ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and ReplayCVE-2025-66844Criticalgetgrav/grav: Grav may be vulnerable to SSRF attack via Twig TemplatesCVE-2025-66843Mediumgetgrav/grav: Grav is vulnerable to Stored XSS through authenticated user-edited contentCVE-2025-65854Criticalmineadmin/mineadmin: MineAdmin has an insecure default passwordCVE-2024-58303Highfof/pretty-mail: FoF Pretty Mail has a server-side template injection vulnerabilityCVE-2025-67737Lowazuracast/azuracast: AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCECVE-2025-67719Criticalibexa/user: Ibexa User Bundle is missing password change validationCVE-2025-67648Highshopware/shopware: Shopware Storefront Reflected XSS in Storefront Login PageGHSA-5J8P-438X-RGG5Criticalonelogin/php-saml: SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475 CVE-2025-67510Criticalneuron-core/neuron-ai: Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)CVE-2025-67509Highneuron-core/neuron-ai: Neuron MySQLSelectTool “read-only” bypass via `SELECT ... INTO OUTFILE` (file write → potential RCE)CVE-2025-67507Highfilament/filament: Filament multi-factor authentication (app) recovery codes can be used multiple timesCVE-2025-66578Mediumrobrichards/xmlseclibs: robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validationCVE-2025-65346Highalexusmai/laravel-file-manager: alexusmai laravel-file-manager is vulnerable to Directory Traversal via the unzip/extraction functionalityCVE-2025-65345Lowalexusmai/laravel-file-manager: alexusmai laravel-file-manager is vulnerable to Directory TraversalCVE-2025-66468Highaimeos/ai-cms-grapesjs: Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editorsCVE-2025-65657Mediumfeehi/cms: FeehiCMS Has a Remote Code Execution via Unrestricted File Upload in Ad ManagementCVE-2025-13827Highmautic/grapes-js-builder-bundle: GrapesJsBuilder File Upload allows all file uploadsCVE-2025-13828Criticalmautic/core: Mautic user without privileged access to the Marketplace can install and uninstall composer packagesCVE-2025-65186Mediumgetgrav/grav: Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor

Stop the waste.
Protect your environment with Kodem.