Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-2WWR-9X6F-88GPMediumeasycorp/easyadmin-bundle: EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig componentsCVE-2026-55219Mediumpaymenter/paymenter: Paymenter has race condition in payWithCredit() that enables credit double-spendCVE-2026-48808Mediumtwig/twig: Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`CVE-2026-48807Mediumtwig/twig: Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filtersCVE-2026-48806Mediumtwig/twig: Twig: Sandbox `__toString()` policy bypass via dynamic mapping keysCVE-2026-48805Lowtwig/twig: Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`CVE-2026-47198Highpaymenter/paymenter: Paymenter has URL parameter injection that bypasses paid plan limits at checkoutCVE-2026-54244Lowstatamic/cms: Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editorsCVE-2026-54243Mediumstatamic/cms: Statamic Vulnerable to CSV formula injection in form submission exportsCVE-2026-54242Mediumstatamic/cms: Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)GHSA-7VFX-4246-JCFHHighsolidinvoice/solidinvoice: SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settingsCVE-2026-49287Highstatamic/cms: Statamic CMS's unsafe method invocation via collection sorting allows data destructionCVE-2026-49288Mediumstatamic/cms: Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resourcesCVE-2026-49359Mediumpontedilana/php-weasyprint: PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment optionCVE-2026-49358Lowpontedilana/php-weasyprint: PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFilesCVE-2026-49286Highpontedilana/php-weasyprint: PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)CVE-2026-49262Lowaimeos/pagible: Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxyCVE-2026-49260Highpontedilana/php-weasyprint: php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of…GHSA-985R-Q3QP-299HHighthorsten/phpmyfaq: phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guardsGHSA-Q683-8468-R6H6Mediumweb-auth/webauthn-symfony-bundle: WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logsCVE-2026-48820Mediumcakephp/cakephp: CakePHP: View::element() is missing a path containment checkCVE-2026-48979Highphp-standard-library/h2: PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smugglingGHSA-J7F5-GFQM-PCX3Mediumpterodactyl/panel: Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in systemCVE-2026-48505Highfilament/filament: Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submissionCVE-2026-54329Highsnipe/snipe-it: Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

Stop the waste.
Protect your environment with Kodem.