Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-X76W-8C62-48MGMediumcraftcms/cms: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permissionCVE-2026-52889Criticalverbb/formie: Formie Hidden field defaults vulnerable to Server-Side Template InjectionCVE-2026-49284Highsimplesamlphp/simplesamlphp: SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion…GHSA-J5MC-P8QG-39J7Lowkimai/kimai: Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark ManipulationCVE-2026-49289Highsimplesamlphp/saml2: SimpleSAMLphp has Possible DoS via XPath TransformCVE-2026-49283Highsimplesamlphp/saml2: SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypassCVE-2026-50282Highcraftcms/cms: Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced MovesCVE-2026-50281Highcraftcms/cms: Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elementsCVE-2026-9811Mediummautic/core: Mautic has Stored Cross-Site Scripting (XSS) in Project Option SelectorCVE-2026-9809Highmautic/core: Mautic has Stored Cross-Site Scripting (XSS) in Projects ComponentCVE-2026-9808Highmautic/core: Mautic has an Authorization Bypass in API v2 EndpointsCVE-2026-9559Criticalmautic/core: Mautic vulnerable to Path Traversal via Campaign ImportCVE-2026-9558Criticalmautic/core: Mautic has Server-Side Template Injection (SSTI) in Theme TemplatesCVE-2026-9557Mediummautic/core: Mautic Focus component Vulnerable to SSRFCVE-2026-4776Highmautic/core: Mautic has SQL Injection in API Contact FilteringGHSA-Q4RM-M6XH-5PV7Mediumfroxlor/froxlor: Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add APIGHSA-MR9H-45P9-FG8HMediumfroxlor/froxlor: Froxlor: Authenticated customers can read other customers' allowed sender aliasesCVE-2026-50284Highcraftcms/cms: Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assetsCVE-2026-50283Mediumcraftcms/cms: Craft CMS: Unauthorized Deletion of Source Assets During File ReplacementCVE-2026-50280Mediumcraftcms/cms: Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save checkCVE-2026-50279Highcraftcms/cms: Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gapCVE-2026-52854Highmediawiki/maps: mediawiki/maps has stored XSS through the overlays parameter in the display_map parser functionGHSA-M492-GV72-XVXJLowkimai/kimai: Kimai Password Reset Link Remains Valid After Password ChangeCVE-2026-49981Hightwig/twig: Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`GHSA-HWMC-R6MF-JH83Lowspatie/schema-org: Schema.org has cross-site scripting (XSS) via script break-out in toScript() output

Stop the waste.
Protect your environment with Kodem.