Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
CVE-2026-59932High· 7.5PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
CVE-2026-59933High· 7.5PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
CVE-2026-59941MediumPoCDompdf: Uncontrolled resource consumption based on declared BMP dimensions
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
CVE-2026-59942MediumDompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
CVE-2026-59943MediumDompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
CVE-2026-55554LowDompdf: Chroot Validation Bypass
Dompdf: Chroot Validation Bypass
CVE-2026-55555LowDompdf: File existence oracle via font-face stylesheet declaration
Dompdf: File existence oracle via font-face stylesheet declaration
CVE-2026-56722MediumDompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
GHSA-f283-ghqc-fg79Medium· 5.3Guzzle: Unbounded response cookies risk denial of service
Guzzle: Unbounded response cookies risk denial of service
GHSA-wm3w-8rrp-j577Medium· 5.9Guzzle: Host-only cookie scope is not preserved
Guzzle: Host-only cookie scope is not preserved
GHSA-h95v-h523-3mw8Medium· 5.9Guzzle: URI fragments disclosed in redirect Referer headers
Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-94pj-82f3-465wMedium· 5.3Guzzle: Proxy-Authorization headers can be sent to origin servers
Guzzle: Proxy-Authorization headers can be sent to origin servers
CVE-2026-59947Medium· 4.7Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
CVE-2026-59946Medium· 6.1Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
CVE-2026-59948High· 7.0Composer: Arbitrary file write outside vendor via malicious transitive package name
Composer: Arbitrary file write outside vendor via malicious transitive package name
GHSA-cvpc-hccg-wmw4Medium· 6.3Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration
CVE-2026-54540High· 8.8Pheditor has an authenticated terminal command whitelist bypass
Pheditor has an authenticated terminal command whitelist bypass
CVE-2026-55578High· 8.8Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
CVE-2026-55579Critical· 9.8PoCPheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
GHSA-v626-428r-43p8High· 6.5Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
GHSA-373m-p57p-8665Medium· 6.1Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
GHSA-xg43-5579-qw6vMedium· 6.5adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
CVE-2026-52883MediumMantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
CVE-2026-62944HighMantisBT: Stored XSS in print_all_bug_page_word.php
MantisBT: Stored XSS in print_all_bug_page_word.php
CVE-2026-50552Medium· 6.3Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
CVE-2026-52847CriticalMantisBT: Reflected XSS in admin/install.php
MantisBT: Reflected XSS in admin/install.php
CVE-2026-52881CriticalMantisBT: Reflected XSS in admin/install.php via unescaped printf
MantisBT: Reflected XSS in admin/install.php via unescaped printf
CVE-2026-52882MediumMantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
CVE-2026-49273HighMantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
CVE-2026-49280MediumMantisBT: REST API unauthorized Issue status change
MantisBT: REST API unauthorized Issue status change