Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-66298Highgetgrav/grav: Grav is vulnerable to Server-Side Template Injection (SSTI) via FormsCVE-2025-66294Highgetgrav/grav: Grav is vulnerable to RCE via SSTI through Twig Sandbox BypassCVE-2025-66310Mediumgetgrav/grav: Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced TabCVE-2025-66309Mediumgetgrav/grav: Grav is vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in…CVE-2025-66297Highgetgrav/grav: Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig InjectionCVE-2025-66308Mediumgetgrav/grav: Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`CVE-2025-66295Highgetgrav/grav: Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System CorruptionCVE-2025-66305Highgetgrav/grav: Grav vulnerable to Denial of Service via Improper Input Handling in 'Supported' ParameterCVE-2025-66306Mediumgetgrav/grav: Grav vulnerable to Information Disclosure via IDOR in Grav Admin PanelCVE-2025-66302Mediumgetgrav/grav: Grav vulnerable to Path Traversal allowing server files backupCVE-2025-66307Mediumgetgrav/grav: Grav Admin Plugin vulnerable to User Enumeration & Email DisclosureCVE-2025-66312Mediumgetgrav/grav: Grav Admin Plugin is vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter…CVE-2025-66311Mediumgetgrav/grav: Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parametersCVE-2025-66304Mediumgetgrav/grav: Grav Exposes Password Hashes Leading to privilege escalationCVE-2025-66303Mediumgetgrav/grav: Grav is vulnerable to a DOS on the admin panelCVE-2025-66301Highgetgrav/grav: Grav has Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actionsCVE-2025-66300Highgetgrav/grav: Grav is vulnerable to Arbitrary File ReadCVE-2025-66299Highgetgrav/grav: Grav is Vulnerable to Security Sandbox Bypass with SSTI (Server Side Template Injection)CVE-2025-66296Highgetgrav/grav: Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account TakeoverCVE-2025-65622Mediumsnipe/snipe-it: Snipe-IT allows stored XSS via the Locations "Country" fieldCVE-2025-65621Mediumsnipe/snipe-it: Snipe-IT is vulnerable to stored cross-site scriptingCVE-2025-63520Mediumfeehi/feehicms: FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update functionCVE-2025-63522Mediumfeehi/feehicms: FeehiCMS is vulnerable to reverse tabnabbingCVE-2025-63523Mediumfeehi/feehicms: FeehiCMS fails to enforce server-side immutabilityCVE-2025-13784Lowyungifez/skuul: yungifez Skuul School Management System vulnerable to XSS via SVG

Stop the waste.
Protect your environment with Kodem.