Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-62519Highthorsten/phpmyfaq: phpMyFAQ has Authenticated SQL Injection in Configuration Update FunctionalityGHSA-2W46-VQ8H-98VHMediumshopware/core: Shopware 6's password recovery link does not expire after email changeCVE-2025-64711Lowprivatebin/privatebin: PrivateBin vulnerable to malicious filename use for self-XSS / HTML injection locally for usersCVE-2025-64714Mediumprivatebin/privatebin: PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversalCVE-2025-64500Highsymfony/http-foundation: Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypassCVE-2025-12998Highcodingms/modules: TYPO3 Modules Extension has Improper Authentication vulnerability CVE-2025-64519Hightorrentpier/torrentpier: TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameterCVE-2025-12918Lowyungifez/skuul: Skuul School Management System has an Insecure Direct Object Reference (IDOR) Vulnerability in View Fee InvoiceCVE-2025-64174Mediumopenmage/magento-lts: OpenMage vulnerable to XSS in Admin NotificationsCVE-2025-62520Mediummantisbt/mantisbt: MantisBT unauthorized disclosure of private project column configurationCVE-2025-55155Mediummantisbt/mantisbt: MantisBT lacks verification when changing a user's email addressCVE-2025-46556Mediummantisbt/mantisbt: MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note LengthCVE-2025-47776Highmantisbt/mantisbt: MantisBT vulnerable to authentication bypass for some passwords due to PHP type jugglingCVE-2025-64112Highstatamic/cms: Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side ValidationCVE-2025-9954Highdrupal/acquia_dam: Drupal Acquia DAM allows Forceful BrowsingCVE-2025-12083Mediumdrupal/civictheme: Drupal CivicTheme Design System allows Cross-Site Scripting (XSS)CVE-2025-12466Highdrupal/simple_oauth: Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication BypassCVE-2025-12082Highdrupal/civictheme: Drupal CivicTheme Design System allows Forceful BrowsingCVE-2025-10927Mediumdrupal/plausible_tracking: Drupal Plausible tracking is vulnerable to XSSCVE-2025-10930Mediumdrupal/currency: Drupal Currency allows Cross Site Request ForgeryCVE-2025-10928Mediumdrupal/access_code: Drupal Access code allows Brute Force AttemptsCVE-2025-10931Lowdrupal/umami_analytics: Drupal Umami Analytics allows Cross-Site Scripting (XSS)CVE-2025-10929Mediumdrupal/reverse_proxy_header: Drupal Reverse Proxy Header allows Manipulating User-Controlled VariablesCVE-2025-10926Mediumdrupal/json_field: Drupal JSON Field is vulnerable to XSSCVE-2025-62798Mediumcode16/sharp: Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax

Stop the waste.
Protect your environment with Kodem.