Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-13785Lowyungifez/skuul: Skuul School Management System has a Sensitive Data Exposure Vulnerability in Uploaded ImagesCVE-2025-66026Mediumredaxo/source: REDAXO CMS is vulnerable to Reflected XSS in Mediapool Info Banner via args[types]CVE-2025-65961Lowcontao/core-bundle: Contao is vulnerable to cross-site scripting in templatesCVE-2025-65960Mediumcontao/core-bundle: Contao is vulnerable to remote code execution in template closuresCVE-2025-64049Mediumredaxo/source: REDAXO CMS is vulnerable to XSS through its module management componentCVE-2025-64050Highredaxo/source: REDAXO CMS is vulnerable to RCE attack through its template management componentCVE-2025-65956Mediumgetformwork/formwork: Formwork CMS has Stored Cross-Site Scripting Vulnerebility in Blog TagsCVE-2025-64027Mediumsnipe/snipe-it: Snipe-IT has Cross-site Scripting vulnerability in CSV import workflowCVE-2025-60798Mediumphppgadmin/phppgadmin: phppgadmin contains a SQL injection vulnerabilityCVE-2025-60799Mediumphppgadmin/phppgadmin: phppgadmin contains an incorrect access control vulnerabilityCVE-2025-60796Lowphppgadmin/phppgadmin: phppgadmin vulnerable to Cross-site ScriptingCVE-2025-60797Mediumphppgadmin/phppgadmin: phppgadmin contains a SQL injection vulnerabilityCVE-2025-65103Highdevcode-it/openstamanager: OpenSTAManager has Authenticated SQL Injection in API via 'display' parameterCVE-2025-12119Mediummongodb/mongodb-extension: MongoDB driver extension affected by mongoc_bulk_operation_t's read of invalid memoryCVE-2025-65093Mediumlibrenms/librenms: LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpointCVE-2025-63828Mediumbackdrop/backdrop: Backdrop CMS Host Header Injection vulnerabilityCVE-2025-13081Mediumdrupal/core: Drupal core allows Object InjectionCVE-2025-13082Lowdrupal/core: Drupal core allows Content SpoofingCVE-2025-13080Lowdrupal/core: Drupal core allows Forceful BrowsingCVE-2025-13083Lowdrupal/core: Drupal core allows Exploiting Incorrectly Configured Access Control Security LevelsCVE-2025-12760Mediumdrupal/email_tfa: Drupal Email TFA allows Functionality BypassCVE-2025-12761Lowdrupal/simple_multistep: Drupal Simple multi step form allows Cross-Site ScriptingCVE-2025-65014Lowlibrenms/librenms: LibreNMS has Weak Password PolicyCVE-2025-65013Mediumlibrenms/librenms: LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameter `Image Name` CVE-2025-65012Mediumgetkirby/cms: Kirby CMS has cross-site scripting (XSS) in the changes dialog

Stop the waste.
Protect your environment with Kodem.