Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-47156Criticalmantisbt/mantisbt: MantisBT: SOAP API Authentication Bypass with Privilege Escalation to AdministratorCVE-2026-47142Highmantisbt/mantisbt: MantisBT: SQL Injection via history_order Configuration ValueGHSA-HGJX-R89M-M7V4Criticalfacturascripts/facturascripts: FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCECVE-2026-54087Higheasycorp/easyadmin-bundle: EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageFieldCVE-2026-50157Mediumauth0/symfony: Auth0 Symfony SDK Accepted Bearer Tokens via URL Query ParameterCVE-2026-45710Lowfacturascripts/facturascripts: FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes…CVE-2026-45263Highfacturascripts/facturascripts: FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens…CVE-2026-45693Highfacturascripts/facturascripts: FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles DocumentsCVE-2026-45262Criticalfacturascripts/facturascripts: FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`CVE-2026-52828Mediumkimai/kimai: Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD AccessCVE-2026-52827Highkimai/kimai: Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTPCVE-2026-52826Mediumkimai/kimai: Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate ManipulationCVE-2026-52825Mediumkimai/kimai: Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized…CVE-2026-52824Criticalkimai/kimai: Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account TakeoverCVE-2026-52823Mediumkimai/kimai: Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State ChangesCVE-2026-52822Mediumkimai/kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access RevocationCVE-2026-52821Mediumkimai/kimai: Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized ProjectsCVE-2026-52820Mediumkimai/kimai: Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypassCVE-2026-52819Mediumkimai/kimai: Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the…CVE-2026-49992Mediumkimai/kimai: Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure ChangesCVE-2026-47677Criticalfacturascripts/facturascripts: FacturaScripts: Account takeover of any 2FA-enabled userCVE-2026-49970Highplank/laravel-mediable: Laravel-Mediable: path traversal vulnerability in the File::sanitizePath()CVE-2026-55372Highnukeviet/nukeviet: NukeViet: Pre-authentication SSRF via X-Forwarded-HostCVE-2026-54065Highnukeviet/nukeviet: NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment FunctionCVE-2026-54064Highnukeviet/nukeviet: NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module

Stop the waste.
Protect your environment with Kodem.