Tagged “composer”
CVEs tagged composer, newest first.
478 CVEsRSS
CVE-2026-71537Medium· 6.5Paymenter is a free and open-source webshop solution for management of hosting services
Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later execut…
GHSA-jr78-w6w5-m8f8High· 7.3Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
GHSA-9rcc-pmj8-ffhrMedium· 6.1Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
CVE-2026-77616Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added…
CVE-2026-77610Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`)…
CVE-2026-77609Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and is…
CVE-2026-77607Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML…
CVE-2026-77606Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. U…
CVE-2026-77608Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when the `value` parameter was reflected back into rendered output and error messaging…
CVE-2025-61682High· 8.6PoCSemantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as…
CVE-2026-72697High· 6.5Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
CVE-2026-72695High· 8.1Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
CVE-2026-45140Critical· 9.8PoCChamilo LMS is an open-source learning management system
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …
CVE-2026-72702LowGrav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match
Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match
CVE-2026-72701Low· 3.7Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection
Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection
CVE-2026-72698High· 6.5Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
CVE-2026-76846High· 7.5Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
CVE-2026-76839High· 7.7Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
CVE-2026-65608High· 8.8Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
CVE-2026-69088High· 8.1Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
CVE-2026-69089HighGrav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
CVE-2026-61449Medium· 6.5Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
CVE-2026-79752Critical· 9.2PoCCakePHP is a rapid development framework for PHP
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBui…
CVE-2026-61453MediumGrav: XSS Blueprint Validation Bypass via Twig String Concatenation
Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
CVE-2026-58657Medium· 4.8Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
CVE-2026-84997High· 7.5PoCreact/http is an event-driven, streaming HTTP client and server implementation for ReactPHP
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body …
CVE-2026-56831Medium· 6.5PoCShopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Di…
CVE-2026-56830Medium· 6.5Shopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used …
CVE-2026-56829High· 8.1PoCShopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…
CVE-2026-56827High· 8.1PoCShopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.ph…