Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-47939Mediumtypo3/cms-core: TYPO3 Allows Unrestricted File Upload in File Abstraction LayerCVE-2025-47938Lowtypo3/cms-core: TYPO3 Unverified Password Change for Backend UsersCVE-2025-47937Lowtypo3/cms-core: TYPO3 Allows Information Disclosure via DBAL Restriction HandlingCVE-2025-47936Lowtypo3/cms-webhooks: TYPO3 CMS Webhooks Server Side Request ForgeryCVE-2025-47946Mediumsymfony/ux-twig-component: Symfony UX allows unsanitized HTML attribute injection via ComponentAttributesCVE-2025-47931Lowlibrenms/librenms: LibreNMS stored Cross-site Scripting vulnerability in poller group nameGHSA-9FWJ-9MJF-RHJ3Criticalauth0/login: laravel-auth0 SDK Vulnerable to Brute Force Authentication Tags of CookieStore SessionsGHSA-2F4R-34M4-3W8QCriticalauth0/wordpress: Auth0 Wordpress plugin Vulnerable to Brute Force Authentication Tags of CookieStore SessionsGHSA-9WG9-93H9-J8CHCriticalauth0/symfony: Auth0 Symfony SDK Vulnerable to Brute Force Authentication Tags of CookieStore SessionsCVE-2025-47275Criticalauth0/auth0-php: Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDKCVE-2024-11718Mediumcouleurcitron/tarteaucitron-wp: tarteaucitron-wp WordPress Plugin Vulnerable to Stored Cross-Site ScriptingCVE-2025-47778Mediumsulu/sulu: Sulu vulnerable to XXE in SVG File upload InspectorCVE-2025-30159Mediumgetkirby/kirby: Kirby vulnerable to path traversal of snippet names in the `snippet()` helperCVE-2025-30207Lowgetkirby/cms: Kirby vulnerable to path traversal in the router for PHP's built-in serverCVE-2025-31493Mediumgetkirby/cms: Kirby vulnerable to path traversal of collection names during file system lookupCVE-2024-56526Highoxid-esales/oxideshop-ce: OXID eShop May Display User InformationCVE-2025-35939Mediumcraftcms/cms: Craft CMS stores arbitrary content provided by unauthenticated users in session filesCVE-2025-29746Mediumkoillection/koillection: Koillection Cross Site Scripting vulnerability CVE-2025-29448Mediumalextselegidis/easyappointments: Easy!Appointments Denial of Service (DoS)CVE-2025-46734Mediumleague/commonmark: league/commonmark contains a XSS vulnerability in Attributes extensionCVE-2025-46731Highcraftcms/cms: Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTICVE-2024-51991Lowoctober/system: October CMS Allows Unprotected SVG Rename in Media ManagerCVE-2025-47226Mediumsnipe/snipe-it: Grokability Snipe-IT has incorrect authorization for accessing asset informationCVE-2025-46337Criticaladodb/adodb-php: SQL injection in ADOdb PostgreSQL driver pg_insert_id() methodCVE-2025-0520Criticalshowdoc/showdoc: ShowDoc unrestricted file upload vulnerability

Stop the waste.
Protect your environment with Kodem.