VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

CVE-2026-59932High· 7.5
2mo ago

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.70%via GHSA
CVE-2026-59933High· 7.5
2mo ago

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.70%via GHSA
CVE-2026-59941MediumPoC
2mo ago

Dompdf: Uncontrolled resource consumption based on declared BMP dimensions

Dompdf: Uncontrolled resource consumption based on declared BMP dimensions

▾ Twilightdompdf · dompdf/dompdfEPSS 0.64%via GHSA
CVE-2026-59942Medium
2mo ago

Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps

Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.90%via GHSA
CVE-2026-59943Medium
2mo ago

Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem

Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.42%via GHSA
CVE-2026-55554Low
2mo ago

Dompdf: Chroot Validation Bypass

Dompdf: Chroot Validation Bypass

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.45%via GHSA
CVE-2026-55555Low
2mo ago

Dompdf: File existence oracle via font-face stylesheet declaration

Dompdf: File existence oracle via font-face stylesheet declaration

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.51%via GHSA
CVE-2026-56722Medium
2mo ago

Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI

Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.45%via GHSA
GHSA-f283-ghqc-fg79Medium· 5.3
2mo ago

Guzzle: Unbounded response cookies risk denial of service

Guzzle: Unbounded response cookies risk denial of service

▾ Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-wm3w-8rrp-j577Medium· 5.9
2mo ago

Guzzle: Host-only cookie scope is not preserved

Guzzle: Host-only cookie scope is not preserved

▾ Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-h95v-h523-3mw8Medium· 5.9
2mo ago

Guzzle: URI fragments disclosed in redirect Referer headers

Guzzle: URI fragments disclosed in redirect Referer headers

▾ Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-94pj-82f3-465wMedium· 5.3
2mo ago

Guzzle: Proxy-Authorization headers can be sent to origin servers

Guzzle: Proxy-Authorization headers can be sent to origin servers

▾ Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
CVE-2026-59947Medium· 4.7
2mo ago

Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

▾ Sunlitcomposer · composer/composerEPSS 0.14%via GHSA
CVE-2026-59946Medium· 6.1
2mo ago

Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

▾ Sunlitcomposer · composer/composerEPSS 0.17%via GHSA
CVE-2026-59948High· 7.0
2mo ago

Composer: Arbitrary file write outside vendor via malicious transitive package name

Composer: Arbitrary file write outside vendor via malicious transitive package name

▾ Twilightcomposer · composer/composerEPSS 0.16%via GHSA
GHSA-cvpc-hccg-wmw4Medium· 6.3
2mo ago

Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration

Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration

▾ Sunlitverbb · verbb/formievia GHSA
CVE-2026-54540High· 8.8
2mo ago

Pheditor has an authenticated terminal command whitelist bypass

Pheditor has an authenticated terminal command whitelist bypass

▾ Twilightpheditor · pheditor/pheditorEPSS 0.73%via GHSA
CVE-2026-55578High· 8.8
2mo ago

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

▾ Twilightpheditor · pheditor/pheditorEPSS 0.67%via GHSA
CVE-2026-55579Critical· 9.8PoC
2mo ago

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

▾ Abyssalpheditor · pheditor/pheditorEPSS 0.79%via GHSA
GHSA-v626-428r-43p8High· 6.5
2mo ago

Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-373m-p57p-8665Medium· 6.1
2mo ago

Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

▾ Sunlitgetgrav · getgrav/gravvia GHSA
GHSA-xg43-5579-qw6vMedium· 6.5
2mo ago

adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files

adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files

▾ Sunlitadawolfa · adawolfa/isdocvia GHSA
CVE-2026-52883Medium
2mo ago

MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs

MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs

▾ Sunlitmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-62944High
2mo ago

MantisBT: Stored XSS in print_all_bug_page_word.php

MantisBT: Stored XSS in print_all_bug_page_word.php

▾ Twilightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-50552Medium· 6.3
2mo ago

Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail

Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail

▾ Sunlitphanan · phanan/koelEPSS 0.27%via GHSA
CVE-2026-52847Critical
2mo ago

MantisBT: Reflected XSS in admin/install.php

MantisBT: Reflected XSS in admin/install.php

▾ Midnightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-52881Critical
2mo ago

MantisBT: Reflected XSS in admin/install.php via unescaped printf

MantisBT: Reflected XSS in admin/install.php via unescaped printf

▾ Midnightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-52882Medium
2mo ago

MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters

MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters

▾ Sunlitmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-49273High
2mo ago

MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php

MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php

▾ Twilightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-49280Medium
2mo ago

MantisBT: REST API unauthorized Issue status change

MantisBT: REST API unauthorized Issue status change

▾ Sunlitmantisbt · mantisbt/mantisbtvia GHSA
CVEs tagged “composer” — page 11 · VulnSea