Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
GHSA-32rq-jhr7-m3hhMedium· 5.3Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
GHSA-3fvr-2jw6-crq4Medium· 5.3Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
GHSA-mqq9-gxg5-m58gHigh· 5.9Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-mjrx-74jh-7xgwHigh· 5.9Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
CVE-2026-57232Low· 3.1Contao is an Open Source CMS
Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to feedIo->read() without scheme or priv…
CVE-2026-63220Medium· 4.8CodeIgniter is a PHP full-stack web framework
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers an…
CVE-2026-63221Critical· 9.4CodeIgniter is a PHP full-stack web framework
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled conditio…
CVE-2026-63222High· 7.5CodeIgniter is a PHP full-stack web framework
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to w…
CVE-2026-55824Low· 2.6Contao is an Open Source CMS
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to ext…
CVE-2026-54768MediumWPGraphQL provides a GraphQL API for WordPress sites
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordR…
CVE-2026-53599High· 7.5REDAXO is a PHP-based content management system
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/…
CVE-2026-68500High· 7.5Sylius Mollie Plugin provides Mollie payment integration for Sylius applications
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId paramete…
CVE-2026-68501Medium· 6.5Sylius Mollie Plugin provides Mollie payment integration for Sylius applications
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCode…
CVE-2026-55651High· 7.1Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
CVE-2026-52840Low· 2.7Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
CVE-2026-52839Low· 3.3Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
CVE-2026-52837MediumEasy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
CVE-2026-52841Low· 3.1Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
CVE-2026-52838Low· 2.6Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
CVE-2026-54588Critical· 9.6Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
CVE-2026-54593High· 8.1Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
CVE-2026-61609High· 7.5Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
CVE-2026-45293High· 8.6WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rule…
GHSA-g3hq-hphg-8fhhHigh· 8.8Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
GHSA-f25v-x6vr-962gCritical· 10.0Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
GHSA-h4hf-v6w5-897xHigh· 8.8Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
GHSA-rm67-g9ch-vxffHigh· 8.1Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
GHSA-cmwh-g2h8-c222High· 8.1Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
GHSA-pp9r-ppc4-25w4High· 8.8Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
CVE-2026-59931High· 7.7PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist