Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
CVE-2026-48820MediumCakePHP: View::element() is missing a path containment check
CakePHP: View::element() is missing a path containment check
GHSA-q683-8468-r6h6MediumWebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
GHSA-985r-q3qp-299hHigh· 8.1phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards
phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards
CVE-2026-49260High· 8.2php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)
php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)
CVE-2026-49286High· 8.1PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
CVE-2026-49358Low· 3.0PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
CVE-2026-49359Medium· 6.5PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
CVE-2026-49288Medium· 4.3Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
CVE-2026-49287High· 7.4Statamic CMS's unsafe method invocation via collection sorting allows data destruction
Statamic CMS's unsafe method invocation via collection sorting allows data destruction
GHSA-7vfx-4246-jcfhHighSolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings
SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings
CVE-2026-54242Medium· 4.9Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
CVE-2026-54243Medium· 6.1Statamic Vulnerable to CSV formula injection in form submission exports
Statamic Vulnerable to CSV formula injection in form submission exports
CVE-2026-54244Low· 3.5Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
CVE-2026-48505High· 7.4Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
GHSA-32fw-h446-j4hhHigh· 6.5Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload
Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload
CVE-2026-55173High· 8.1AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink
AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink
GHSA-7cqp-7cfv-6c3qMediumAVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel
AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel
CVE-2026-48157Medium· 6.1Slim has Reflected XSS in the HtmlErrorRenderer
Slim has Reflected XSS in the HtmlErrorRenderer
CVE-2026-48166Medium· 5.3Filament: Timing-based user enumeration on login page
Filament: Timing-based user enumeration on login page
CVE-2026-48167Medium· 6.4Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS
Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS
CVE-2026-48488LowphpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
CVE-2026-48492MediumSnipe-IT's selectlist visibility is too permissive
Snipe-IT's selectlist visibility is too permissive
CVE-2026-48493Medium· 5.5Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
CVE-2026-48500Medium· 6.5Filament: Unauthenticated temporary file upload on auth pages
Filament: Unauthenticated temporary file upload on auth pages
CVE-2026-48507High· 7.1Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
CVE-2026-49205Medium· 6.5phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
CVE-2026-55542LowSnipe-IT's S3 signature image retrieval lacks authorization before temporary URL
Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
CVE-2026-54329High· 8.5Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
CVE-2026-33684Medium· 5.3AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions
AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions
CVE-2026-33692High· 7.5AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration
AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration