Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-62418Mediumbagisto/bagisto: bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)CVE-2025-62416Mediumbagisto/bagisto: bagisto has Server Side Template Injection (SSTI) in Product DescriptionCVE-2025-62412Lowlibrenms/librenms: LibreNMS alert-rules has a Cross-Site Scripting VulnerabilityCVE-2025-61924Lowprestashop/ps_checkout: PrestaShop Checkout Target PayPal merchant account hijacking from backofficeCVE-2025-61923Mediumprestashop/ps_checkout: PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosureCVE-2025-61922Criticalprestashop/ps_checkout: PrestaShop Checkout allows customer account takeover via emailCVE-2025-62415Mediumbagisto/bagisto: bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)CVE-2025-62411Mediumlibrenms/librenms: LibreNMS has a Stored XSS vulnerability in its Alert Transport name fieldCVE-2025-54265Mediummagento/community-edition: Magento allows incorrect authorizationCVE-2025-54263Highmagento/community-edition: Magento provides incorrect authorization through a security feature bypassCVE-2025-54267Mediummagento/project-community-edition: Magento vulnerable to privilege escalation due to incorrect authorizationCVE-2025-54266Mediummagento/project-community-edition: Magento vulnerable to stored Cross-Site Scripting (XSS)CVE-2025-54264Highmagento/project-community-edition: Magento vulnerable to stored Cross-Site Scripting (XSS)CVE-2025-62365Mediumlibrenms/librenms: LibreNMS is vulnerable to Reflected-XSS in `report_this` functionCVE-2025-60880Highbagisto/bagisto: Bagisto is vulnerable to XSS through Admin Panel's product creation pathCVE-2025-60868Mediumalt-design/alt-redirect: Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flawCVE-2025-11570Lowdrupal-pattern-lab/unified-twig-extensions: drupal-pattern-lab/unified-twig-extensions is vulnerable to XXSCVE-2025-61183Mediumwebreinvent/vaahcms: VaahCMS is vulnerable to XSS through its Avatar Upload endpointCVE-2025-10352Criticalmelisplatform/melis-core: Melis Platform CMS Unauthenticated Admin Account CreationCVE-2025-10353Criticalmelisplatform/melis-cms-slider: Melis Platform CMS Unauthenticated File Upload Leading to RCECVE-2025-10351Criticalmelisplatform/melis-cms: Melis Platform CMS SQL InjectionCVE-2025-11322Lownovosga/novosga: NovoSGA: Manipulation of User Creation Page can lead to weak password requirementsCVE-2025-59943Highthorsten/phpmyfaq: phpMyFAQ duplicate email registration allows multiple accounts with the same emailCVE-2025-56588Highdolibarr/dolibarr: Dolibarr vulnerable to RCE via the computed field parameterGHSA-7JP2-5H22-M432Lowauth0/symfony: Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import

Stop the waste.
Protect your environment with Kodem.