Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-51489Mediummoonshine/moonshine: MoonShine Arbitrary File Upload VulnerabilityCVE-2025-55296Mediumlibrenms/librenms: LibreNMS allows stored XSS in Alert Template name fieldCVE-2025-52392Highsoosyze/soosyze: Soosyze CMS's /user/login endpoint missing rate-limiting and lockout mechanismsCVE-2025-55166Mediumenshrined/svg-sanitize: svg-sanitizer Bypasses Attribute SanitizationCVE-2025-49554Highmagento/project-community-edition: Magento vulnerable to denial of serviceCVE-2025-49559Mediummagento/project-community-edition: Magento vulnerable to path traversalCVE-2025-49557Highmagento/community-edition: Magento Cross-site Scripting vulnerabilityCVE-2025-49556Highmagento/project-community-edition: Magento has incorrect authorization issue that leads to arbitrary file system readCVE-2025-49558Mediummagento/project-community-edition: Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilityCVE-2025-49555Highmagento/project-community-edition: Magento Cross-Site Request Forgery (CSRF) vulnerabilityCVE-2025-54417Mediumcraftcms/cms: Craft CMS has a theoretical bypass for CVE-2025-23209CVE-2025-7954Mediumshopware/platform: Shopware race condition bypasses voucher restrictionsCVE-2025-8573Lowconcrete5/concrete5: Concrete CMS is vulnerable to Stored XSS from Home Folder on Members Dashboard pageCVE-2025-8571Mediumconcrete5/concrete5: Concrete CMS vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard PageCVE-2025-50706Criticaltopthink/framework: ThinkPHP Path Traversal VulnerabilityCVE-2025-54869Mediumsetasign/fpdi: FPDI allows Memory Exhaustion (OOM) in PDF Parser which leads to Denial of ServiceCVE-2025-54119Criticaladodb/adodb-php: The ADOdb sqlite3 driver allows SQL injectionCVE-2025-51502Mediummicroweber/microweber: Microweber has Reflected XSS Vulnerability in the layout ParameterCVE-2025-51501Mediummicroweber/microweber: Microweber has Reflected XSS Vulnerability in the id ParameterCVE-2025-51504Mediummicroweber/microweber: Microweber XSS Vulnerability in the homepage Endpoint CVE-2025-45769Lowfirebase/php-jwt: php-jwt contains weak encryptionCVE-2025-51503Lowmicroweber/microweber: Microweber Has Stored XSS Vulnerability in User Profile FieldsCVE-2025-45346Highbacula-web/bacula-web: Bacula-web SQL Injection VulnerabilityCVE-2025-8264Highz-push/z-push-dev: z-push/z-push-dev SQL Injection VulnerabilityCVE-2025-54418Criticalcodeigniter4/framework: CodeIgniter4's ImageMagick Handler has Command Injection Vulnerability

Stop the waste.
Protect your environment with Kodem.