Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55542Lowsnipe/snipe-it: Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL CVE-2026-55519Lowsnipe/snipe-it: Snipe-IT has Improper Authorization in File Deletion (IDOR)CVE-2026-55483Mediumsnipe/snipe-it: Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User CreationCVE-2026-55482Mediumsnipe/snipe-it: Snipe-IT has Multi-Tenancy Bypass via Bulk Asset UpdateCVE-2026-50550Mediumsnipe/snipe-it: Snipe-IT has a 2FA reset privilege bypassCVE-2026-49976Mediumsnipe/snipe-it: Snipe-IT Vulnerable to User Account Escalation via CSV ImportCVE-2026-49870Mediumsnipe/snipe-it: Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`CVE-2026-49205Mediumthorsten/phpmyfaq: phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)CVE-2026-48507Highsnipe/snipe-it: Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing usersCVE-2026-48500Mediumfilament/filament: Filament: Unauthenticated temporary file upload on auth pagesCVE-2026-48493Mediumsnipe/snipe-it: Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions AssignmentCVE-2026-48492Mediumsnipe/snipe-it: Snipe-IT's selectlist visibility is too permissiveCVE-2026-48488Lowthorsten/phpmyfaq: phpMyFAQ has Weak Cryptography - SHA1 for Password HashingCVE-2026-48167Mediumfilament/infolists: Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSSCVE-2026-48166Mediumfilament/filament: Filament: Timing-based user enumeration on login pageCVE-2026-48157Mediumslim/slim: Slim has Reflected XSS in the HtmlErrorRendererGHSA-7CQP-7CFV-6C3QMediumwwbn/avideo: AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panelCVE-2026-55173Highwwbn/avideo: AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command…CVE-2026-44585Mediumpaymenter/paymenter: Paymenter has broken object level authorization via service reference manipulation on ticket creationCVE-2026-44584Mediumpaymenter/paymenter: Paymenter doesn't reset email verification status after email changeCVE-2026-44583Mediumpaymenter/paymenter: Paymenter has Blind Unauthenticated SSRF on the Paypal gateway moduleCVE-2026-33731Mediumwwbn/avideo: AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment DataCVE-2026-33692Highwwbn/avideo: AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose ConfigurationCVE-2026-33684Mediumwwbn/avideo: AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet PermissionsCVE-2025-58048Criticalpaymenter/paymenter: Paymenter vulnerable to Remote Code Execution via public file uploads

Stop the waste.
Protect your environment with Kodem.