Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
GHSA-8q6q-m837-fv64Medium· 6.4Koel has SSRF through Authenticated Subsonic podcast feed URLs
Koel has SSRF through Authenticated Subsonic podcast feed URLs
CVE-2026-47142HighMantisBT: SQL Injection via history_order Configuration Value
MantisBT: SQL Injection via history_order Configuration Value
GHSA-hgjx-r89m-m7v4Critical· 9.9FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE
FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE
CVE-2026-45262Critical· 9.9FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`
CVE-2026-45693High· 7.5FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents
FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents
CVE-2026-45263High· 8.0FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export
FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export
CVE-2026-45710Low· 3.5FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
CVE-2026-47677CriticalFacturaScripts: Account takeover of any 2FA-enabled user
FacturaScripts: Account takeover of any 2FA-enabled user
CVE-2026-54064High· 8.7NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
CVE-2026-54065High· 8.7NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
CVE-2026-55372High· 7.2NukeViet: Pre-authentication SSRF via X-Forwarded-Host
NukeViet: Pre-authentication SSRF via X-Forwarded-Host
CVE-2026-48118High· 8.2NukeViet: Unauthenticated Reflected XSS in Comment Module
NukeViet: Unauthenticated Reflected XSS in Comment Module
CVE-2026-49259High· 8.7NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-59193Medium· 4.9Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::…
CVE-2026-54159Critical· 10.0prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
GHSA-qv4m-m73m-8hj7High· 8.8NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
CVE-2026-49858Medium· 5.9API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
CVE-2026-52778Critical· 9.8YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
GHSA-c43v-4cr8-6mvpLowCraft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
GHSA-86vw-x4ww-x467HighCraft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
GHSA-4wj4-79rr-pvffMedium· 4.8Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
CVE-2026-53634Medium· 4.3Sharp Missing Authorization Check in Quick Creation Command Endpoints
Sharp Missing Authorization Check in Quick Creation Command Endpoints
GHSA-gq4g-fpc9-vjfqLowWebauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
CVE-2026-27823CriticalEGroupware has a Remote Code Execution Vulnerability
EGroupware has a Remote Code Execution Vulnerability
CVE-2026-40187HighEGroupware has Authenticated RCE via Malicious eTemplate Upload
EGroupware has Authenticated RCE via Malicious eTemplate Upload
CVE-2026-45016Medium· 6.5EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
CVE-2026-55790HighCraft CMS: DOM XSS via GitHub issue title in CraftSupport widget
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
CVE-2026-55792MediumCraft CMS: Sensitive File Disclosure / Server-Side File Read
Craft CMS: Sensitive File Disclosure / Server-Side File Read
CVE-2026-55793MediumCraft CMS: Stored XSS via Structure entry title in table view
Craft CMS: Stored XSS via Structure entry title in table view
CVE-2026-55794HighCraft CMS: Potential authenticated Remote Code Execution via referrer redirect
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect