Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
GHSA-x76w-8c62-48mgMediumCraft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
GHSA-j5mc-p8qg-39j7LowKimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
CVE-2026-49284High· 7.1SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`
SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`
CVE-2026-9557Medium· 6.4Mautic Focus component Vulnerable to SSRF
Mautic Focus component Vulnerable to SSRF
CVE-2026-9558Critical· 9.9PoCMautic has Server-Side Template Injection (SSTI) in Theme Templates
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
CVE-2026-9559Critical· 9.9Mautic vulnerable to Path Traversal via Campaign Import
Mautic vulnerable to Path Traversal via Campaign Import
CVE-2026-9808High· 7.1Mautic has an Authorization Bypass in API v2 Endpoints
Mautic has an Authorization Bypass in API v2 Endpoints
CVE-2026-9809High· 7.6PoCMautic has Stored Cross-Site Scripting (XSS) in Projects Component
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
CVE-2026-9811Medium· 5.4PoCMautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
CVE-2026-50281HighCraft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
CVE-2026-50282HighCraft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
CVE-2026-50279HighCraft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
CVE-2026-50280MediumCraft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
CVE-2026-50283MediumCraft CMS: Unauthorized Deletion of Source Assets During File Replacement
Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
CVE-2026-50284HighCraft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
GHSA-mr9h-45p9-fg8hMedium· 4.3Froxlor: Authenticated customers can read other customers' allowed sender aliases
Froxlor: Authenticated customers can read other customers' allowed sender aliases
GHSA-q4rm-m6xh-5pv7Medium· 4.3Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API
Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API
CVE-2026-4776High· 7.1Mautic has SQL Injection in API Contact Filtering
Mautic has SQL Injection in API Contact Filtering
GHSA-m492-gv72-xvxjLowKimai Password Reset Link Remains Valid After Password Change
Kimai Password Reset Link Remains Valid After Password Change
GHSA-2wwr-9x6f-88gpMedium· 5.3EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
GHSA-hwmc-r6mf-jh83LowSchema.org has cross-site scripting (XSS) via script break-out in toScript() output
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output
CVE-2026-49981HighTwig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
CVE-2026-48805LowTwig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
CVE-2026-48806MediumTwig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
CVE-2026-48807MediumTwig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
CVE-2026-48808MediumTwig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
CVE-2026-55219Medium· 5.3Paymenter has race condition in payWithCredit() that enables credit double-spend
Paymenter has race condition in payWithCredit() that enables credit double-spend
CVE-2026-47198High· 8.5Paymenter has URL parameter injection that bypasses paid plan limits at checkout
Paymenter has URL parameter injection that bypasses paid plan limits at checkout
GHSA-j7f5-gfqm-pcx3MediumPterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
CVE-2026-48979High· 7.5PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling
PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling