Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-62796Mediumprivatebin/privatebin: PrivateBin is missing HTML sanitization of attached filename in file size hintCVE-2025-62398Mediummoodle/moodle: Moodle does not properly enforce MFACVE-2025-62396Mediummoodle/moodle: Moodle's error handling leads to sensitive information disclosureCVE-2025-62401Mediummoodle/moodle: Moodle has a time restriction bypassCVE-2025-62400Mediummoodle/moodle: Moodle exposed the names of hidden groups to usersCVE-2025-62399Highmoodle/moodle: Moodle vulnerable to brute-force password guessesCVE-2025-62394Mediummoodle/moodle: Moodle sends quiz-related messages to inactive/suspended usersCVE-2025-62393Mediummoodle/moodle: Moodle course access permissions are not properly checked in course_output_fragment_course_overviewCVE-2025-62617Highadmidio/admidio: Admidio Vulnerable to Authenticated SQL Injection in Member Assignment FunctionalityCVE-2025-61457Mediumcode16/sharp: code16 Sharp vulnerable to Cross Site Scripting (XSS)CVE-2025-60790Mediumprocesswire/processwire: ProcessWire CMS vulnerable to resource-exhaustion Denial of ServiceGHSA-R2VG-HVJM-FG38Mediumshopware/platform: Shopware Customer Orders can be canceled, even if refunds are disabledGHSA-27C9-VP3W-6WW8Mediumshopware/platform: Shopware exposes sensitive user information via CSV export mappingGHSA-3CPP-FV95-MPR5Lowshopware/platform: Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoiceGHSA-6WH5-MW9H-5C3WLowshopware/platform: Shopware vulnerable to path traversal via Plugin uploadGHSA-M895-2HJ3-8CG9Mediumshopware/platform: Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individuallyCVE-2025-62508Mediumstarcitizentools/citizen-skin: Citizen vulnerable to stored XSS in sticky header button messagesCVE-2025-61417Lowtastyigniter/tastyigniter: TastyIgniter vulnerable to Cross-Site ScriptingCVE-2025-62671Mediummediawiki/cargo: Cargo Mediawiki Extension vulnerable to Cross-site ScriptingGHSA-8C2G-F8JM-5CR7Mediumibexa/fieldtype-richtext: ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich TextGHSA-2MX6-FQ24-G2MHMediumibexa/admin-ui: ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modalGHSA-99C7-C3MW-MXHVMediumezsystems/ezplatform-admin-ui: ezsystems/ezplatform-admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modalGHSA-Q3X8-6898-23G3Mediumibexa/user: ibexa/user login enumerates user accountsCVE-2025-62414Mediumbagisto/bagisto: bagisto has Cross Site Scripting (XSS) in Create New CustomerCVE-2025-62417Criticalbagisto/bagisto: bagisto has CSV Formula Injection in Create New Product

Stop the waste.
Protect your environment with Kodem.