Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-46346Lowyeswiki/yeswiki: YesWiki Stored XSS Vulnerability in Comments CVE-2025-46347Highyeswiki/yeswiki: YesWiki Remote Code Execution via Arbitrary PHP File Write and ExecutionCVE-2025-46348Criticalyeswiki/yeswiki: YesWiki Vulnerable to Unauthenticated Site Backup Creation and DownloadCVE-2025-46349Highyeswiki/yeswiki: YesWiki Vulnerable to Unauthenticated Reflected Cross-site ScriptingCVE-2025-46350Lowyeswiki/yeswiki: Yeswiki Vulnerable to Authenticated Reflected Cross-site ScriptingCVE-2025-46550Mediumyeswiki/yeswiki: Yeswiki Vulnerable to Unauthenticated Reflected Cross-site ScriptingCVE-2025-46549Mediumyeswiki/yeswiki: Yeswiki Vulnerable to Unauthenticated Reflected Cross-site ScriptingCVE-2025-3647Mediummoodle/moodle: Moodle allows IDOR when accessing the cohorts reportCVE-2025-3645Mediummoodle/moodle: Moodle has an IDOR in messaging web service which allows access to some user detailsCVE-2025-3637Lowmoodle/moodle: Moodle's mod_data edit/delete pages pass CSRF token in GET parameterCVE-2025-3643Mediummoodle/moodle: Moodle has reflected Cross-site Scripting risk in policy toolCVE-2025-3642Highmoodle/moodle: Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repositoryCVE-2025-3641Highmoodle/moodle: Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repositoryCVE-2025-3644Mediummoodle/moodle: Moodle's AJAX section delete does not respect course_can_delete_section()CVE-2025-3638Lowmoodle/moodle: Moodle has a CSRF risk in Brickfield tool's analysis request actionCVE-2025-3640Mediummoodle/moodle: Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other usersCVE-2025-3635Lowmoodle/moodle: Moodle has a CSRF risk in user tours manager that allows tour duplicationCVE-2025-3636Mediummoodle/moodle: Moodle allows IDOR in RSS block, which allows access to additional RSS feedsCVE-2025-3628Mediummoodle/moodle: Moodle reveals student identities through assignment submissions search on anonymous submissionsCVE-2025-32044Highmoodle/moodle: Moodle allows unauthenticated REST API user data exposureCVE-2025-32045Mediummoodle/moodle: Moodle shows hidden grades to users without permission on some grade reportsCVE-2025-3634Mediummoodle/moodle: Moodle self enrollment available before completing second factor with MFA enabledCVE-2025-3627Mediummoodle/moodle: Moodle makes some user data available before completing second factor with MFA enabledCVE-2025-32432Criticalcraftcms/cms: Craft CMS Allows Remote Code ExecutionCVE-2025-26159Mediumnasirkhan/laravel-starter: Laravel Starter Cross Site Scripting (XSS)

Stop the waste.
Protect your environment with Kodem.