VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

478 CVEsRSS

CVE-2026-71537Medium· 6.5
3d ago

Paymenter is a free and open-source webshop solution for management of hosting services

Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later execut…

Sunlitpaymenter · paymenter/paymenterEPSS 0.23%via NVD
GHSA-jr78-w6w5-m8f8High· 7.3
3d ago

Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

Twilightmediawiki · mediawiki/semantic-media-wikivia GHSA
GHSA-9rcc-pmj8-ffhrMedium· 6.1
3d ago

Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

Sunlitmediawiki · mediawiki/semantic-media-wikivia GHSA
CVE-2026-77616Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added…

Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.20%via NVD
CVE-2026-77610Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`)…

Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.15%via NVD
CVE-2026-77609Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and is…

Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.15%via NVD
CVE-2026-77607Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML…

SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.15%via NVD
CVE-2026-77606Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. U…

Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.15%via NVD
CVE-2026-77608Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when the `value` parameter was reflected back into rendered output and error messaging…

Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.15%via NVD
CVE-2025-61682High· 8.6PoC
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as…

Midnightmediawiki · mediawiki/semantic-media-wikiEPSS 0.29%via NVD
CVE-2026-72697High· 6.5
4d ago

Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

Twilightgetgrav · getgrav/gravEPSS 0.31%via GHSA
CVE-2026-72695High· 8.1
4d ago

Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

Twilightgetgrav · getgrav/gravEPSS 0.57%via GHSA
CVE-2026-45140Critical· 9.8PoC
4d ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …

Abyssalchamilo · chamilo-lmsEPSS 0.98%via NVD
CVE-2026-72702Low
4d ago

Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

Sunlitgetgrav · getgrav/gravEPSS 0.10%via GHSA
CVE-2026-72701Low· 3.7
4d ago

Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection

Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection

Sunlitgetgrav · getgrav/gravEPSS 0.18%via GHSA
CVE-2026-72698High· 6.5
4d ago

Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

Twilightgetgrav · getgrav/gravEPSS 0.24%via GHSA
CVE-2026-76846High· 7.5
4d ago

Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

Twilightgetgrav · getgrav/gravEPSS 0.24%via GHSA
CVE-2026-76839High· 7.7
4d ago

Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

Twilightgetgrav · getgrav/gravEPSS 0.27%via GHSA
CVE-2026-65608High· 8.8
4d ago

Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Twilightgetgrav · getgrav/gravEPSS 0.85%via GHSA
CVE-2026-69088High· 8.1
4d ago

Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Twilightgetgrav · getgrav/gravEPSS 0.23%via GHSA
CVE-2026-69089High
4d ago

Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Twilightgetgrav · getgrav/gravEPSS 0.37%via GHSA
CVE-2026-61449Medium· 6.5
4d ago

Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

Sunlitgetgrav · getgrav/gravEPSS 0.44%via GHSA
CVE-2026-79752Critical· 9.2PoC
4d ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBui…

Abyssalcakephp · cakephpEPSS 0.46%via NVD
CVE-2026-61453Medium
5d ago

Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Sunlitgetgrav · getgrav/gravEPSS 0.16%via GHSA
CVE-2026-58657Medium· 4.8
5d ago

Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav

Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav

Sunlitgetgrav · getgrav/gravEPSS 0.37%via GHSA
CVE-2026-84997High· 7.5PoC
5d ago

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body …

Midnightreactphp · httpEPSS 0.55%via NVD
CVE-2026-56831Medium· 6.5PoC
6d ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Di…

Twilightshopperlabs · shopperEPSS 0.41%via NVD
CVE-2026-56830Medium· 6.5
6d ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used …

Sunlitshopperlabs · shopperEPSS 0.36%via NVD
CVE-2026-56829High· 8.1PoC
6d ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…

Midnightshopperlabs · shopperEPSS 0.47%via NVD
CVE-2026-56827High· 8.1PoC
6d ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.ph…

Midnightshopperlabs · shopperEPSS 0.47%via NVD
CVEs tagged “composer” · VulnSea