Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-C42H-56WX-H85QCriticalauth0/login: laravel-auth0 SDK Deserialization of Untrusted Data vulnerabilityGHSA-98J6-67V3-MW34Criticalauth0/symfony: Auth0 Symfony SDK Deserialization of Untrusted Data vulnerabilityCVE-2025-48493Mediumyiisoft/yii2-redis: Yii 2 Redis may expose AUTH parameters in logs in case of connection failureGHSA-862M-5253-832RCriticalauth0/wordpress: Auth0 Wordpress Plugin vulnerable to Deserialization of Untrusted DataCVE-2025-48951Criticalauth0/auth0-php: Auth0-PHP SDK Deserialization of Untrusted Data vulnerabilityCVE-2025-49113Criticalroundcube/roundcubemail: Roundcube Webmail Vulnerable to Authenticated RCE via PHP Object DeserializationCVE-2025-5420Mediumjuzaweb/cms: juzaweb CMS allows cross-site scripting by uploading an SVG fileCVE-2025-48882Highphpoffice/math: PHPOffice Math allows XXE when processing an XML file in the MathML format CVE-2025-5256Mediummautic/core: Mautic has an Open Redirect vulnerability on user unlock path.CVE-2024-47055Mediummautic/core: Mautic segment cloning doesn't have a proper permission checkCVE-2024-47057Mediummautic/core: Mautic allows user name enumeration due to response time difference on password reset formCVE-2024-47056Mediummautic/core: Mautic does not shield .env files from web trafficCVE-2025-5257Mediummautic/core: Mautic's Predictable Page Indexing Might Lead to Sensitive Data ExposureCVE-2025-48883Mediumchrome-php/chrome: Chrome PHP is missing encoding in `CssSelector`CVE-2025-48490Mediumlomkit/laravel-rest-api: Laravel Rest Api has a Search Validation BypassCVE-2025-48200Criticalsjbr/sr-feuser-register: The Front End User Registration extension for TYPO3 (sr_feuser_register) Remote Code ExecutionCVE-2025-48201Highnitsan/ns-backup: The Backup Plus extension for TYPO3 (ns_backup) has a Predictable Resource LocationCVE-2025-48205Highsjbr/sr-feuser-register: The Front End User Registration extension for TYPO3 (sr_feuser_register) allows Insecure Direct Object ReferenceCVE-2025-48206Lownitsan/ns-backup: The Backup Plus extension for TYPO3 (ns_backup) allows XSSCVE-2025-48204Mediumnitsan/ns-backup: The Backup Plus extension for TYPO3 (ns_backup) allows command injectionsCVE-2025-48207Mediumrenolit/reint-downloadmanager: reint_downloadmanager TYPO3 Extension is susceptible to Insecure Direct Object ReferenceCVE-2025-48202Mediumin2code/femanager: The femanager TYPO3 extension allows Insecure Direct Object ReferenceCVE-2025-48203Mediumclickstorm/cs-seo: [clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerabilityCVE-2025-47941Hightypo3/cms-backend: The TYPO3 CMS Backend has Broken Authentication in Backend MFACVE-2025-47940Hightypo3/cms-core: TYPO3 Allows Privilege Escalation to System Maintainer

Stop the waste.
Protect your environment with Kodem.