VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

CVE-2026-48820Medium
3mo ago

CakePHP: View::element() is missing a path containment check

CakePHP: View::element() is missing a path containment check

▾ Sunlitcakephp · cakephp/cakephpEPSS 0.37%via GHSA
GHSA-q683-8468-r6h6Medium
3mo ago

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

▾ Sunlitweb-auth · web-auth/webauthn-symfony-bundlevia GHSA
GHSA-985r-q3qp-299hHigh· 8.1
3mo ago

phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards

phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards

▾ Twilightthorsten · thorsten/phpmyfaqvia GHSA
CVE-2026-49260High· 8.2
3mo ago

php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)

php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)

▾ Twilightpontedilana · pontedilana/php-weasyprintEPSS 0.22%via GHSA
CVE-2026-49286High· 8.1
3mo ago

PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)

PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)

▾ Twilightpontedilana · pontedilana/php-weasyprintEPSS 0.95%via GHSA
CVE-2026-49358Low· 3.0
3mo ago

PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles

PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles

▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.15%via GHSA
CVE-2026-49359Medium· 6.5
3mo ago

PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option

PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option

▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.42%via GHSA
CVE-2026-49288Medium· 4.3
3mo ago

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

▾ Sunlitstatamic · statamic/cmsEPSS 0.27%via GHSA
CVE-2026-49287High· 7.4
3mo ago

Statamic CMS's unsafe method invocation via collection sorting allows data destruction

Statamic CMS's unsafe method invocation via collection sorting allows data destruction

▾ Twilightstatamic · statamic/cmsEPSS 0.46%via GHSA
GHSA-7vfx-4246-jcfhHigh
3mo ago

SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings

SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings

▾ Twilightsolidinvoice · solidinvoice/solidinvoicevia GHSA
CVE-2026-54242Medium· 4.9
3mo ago

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

▾ Sunlitstatamic · statamic/cmsEPSS 0.23%via GHSA
CVE-2026-54243Medium· 6.1
3mo ago

Statamic Vulnerable to CSV formula injection in form submission exports

Statamic Vulnerable to CSV formula injection in form submission exports

▾ Sunlitstatamic · statamic/cmsEPSS 0.34%via GHSA
CVE-2026-54244Low· 3.5
3mo ago

Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors

Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors

▾ Sunlitstatamic · statamic/cmsEPSS 0.30%via GHSA
CVE-2026-48505High· 7.4
3mo ago

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

▾ Twilightfilament · filament/filamentEPSS 0.30%via GHSA
GHSA-32fw-h446-j4hhHigh· 6.5
3mo ago

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-55173High· 8.1
3mo ago

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

▾ Twilightwwbn · wwbn/avideoEPSS 3.4%via GHSA
GHSA-7cqp-7cfv-6c3qMedium
3mo ago

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

▾ Sunlitwwbn · wwbn/avideovia GHSA
CVE-2026-48157Medium· 6.1
3mo ago

Slim has Reflected XSS in the HtmlErrorRenderer

Slim has Reflected XSS in the HtmlErrorRenderer

▾ Sunlitslim · slim/slimEPSS 0.26%via GHSA
CVE-2026-48166Medium· 5.3
3mo ago

Filament: Timing-based user enumeration on login page

Filament: Timing-based user enumeration on login page

▾ Sunlitfilament · filament/filamentEPSS 0.34%via GHSA
CVE-2026-48167Medium· 6.4
3mo ago

Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS

Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS

▾ Sunlitfilament · filament/infolistsEPSS 0.25%via GHSA
CVE-2026-48488Low
3mo ago

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

▾ Sunlitthorsten · thorsten/phpmyfaqEPSS 0.28%via GHSA
CVE-2026-48492Medium
3mo ago

Snipe-IT's selectlist visibility is too permissive

Snipe-IT's selectlist visibility is too permissive

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.39%via GHSA
CVE-2026-48493Medium· 5.5
3mo ago

Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment

Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.31%via GHSA
CVE-2026-48500Medium· 6.5
3mo ago

Filament: Unauthenticated temporary file upload on auth pages

Filament: Unauthenticated temporary file upload on auth pages

▾ Sunlitfilament · filament/filamentEPSS 0.34%via GHSA
CVE-2026-48507High· 7.1
3mo ago

Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users

Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users

▾ Twilightsnipe · snipe/snipe-itEPSS 0.42%via GHSA
CVE-2026-49205Medium· 6.5
3mo ago

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

▾ Sunlitthorsten · thorsten/phpmyfaqEPSS 0.39%via GHSA
CVE-2026-55542Low
3mo ago

Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL

Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.28%via GHSA
CVE-2026-54329High· 8.5
3mo ago

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

▾ Twilightsnipe · snipe/snipe-itEPSS 0.39%via GHSA
CVE-2026-33684Medium· 5.3
3mo ago

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

▾ Sunlitwwbn · wwbn/avideoEPSS 0.33%via GHSA
CVE-2026-33692High· 7.5
3mo ago

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

▾ Twilightwwbn · wwbn/avideoEPSS 0.45%via GHSA
CVEs tagged “composer” — page 14 · VulnSea