VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

CVE-2026-33731Medium· 6.5
3mo ago

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

▾ Sunlitwwbn · wwbn/avideoEPSS 0.21%via GHSA
CVE-2026-44583Medium· 5.3
3mo ago

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.41%via GHSA
CVE-2026-44584Medium· 4.3
3mo ago

Paymenter doesn't reset email verification status after email change

Paymenter doesn't reset email verification status after email change

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.16%via GHSA
CVE-2026-44585Medium· 5.4
3mo ago

Paymenter has broken object level authorization via service reference manipulation on ticket creation

Paymenter has broken object level authorization via service reference manipulation on ticket creation

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.29%via GHSA
GHSA-xj9w-cgqg-q897Medium· 6.5
3mo ago

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

▾ Sunlitwwbn · wwbn/avideovia GHSA
GHSA-rg7q-4223-phjwHigh· 7.5
3mo ago

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideovia GHSA
CVE-2026-55568Medium· 5.9
3mo ago

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

▾ Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.15%via GHSA
CVE-2026-55766Medium· 4.8
3mo ago

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.23%via GHSA
CVE-2026-55767Medium· 5.8
3mo ago

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

▾ Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.21%via GHSA
CVE-2026-49208Medium
3mo ago

ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor

ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.41%via GHSA
CVE-2026-49209Low
3mo ago

symfony/ux-live-component: Denial of service via unbounded batch action requests

symfony/ux-live-component: Denial of service via unbounded batch action requests

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.56%via GHSA
CVE-2026-49210Medium
3mo ago

symfony/ux-live-component: XSS via attacker-controlled child component tag

symfony/ux-live-component: XSS via attacker-controlled child component tag

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.34%via GHSA
CVE-2026-49211Medium
3mo ago

symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil

symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil

▾ Sunlitsymfony · symfony/ux-autocompleteEPSS 0.53%via GHSA
CVE-2026-49212Low
3mo ago

symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding

symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.24%via GHSA
CVE-2026-49215Low
3mo ago

symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted

symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.18%via GHSA
CVE-2026-49216Medium
3mo ago

symfony/ux-autocomplete: XSS via unescaped AJAX response data

symfony/ux-autocomplete: XSS via unescaped AJAX response data

▾ Sunlitsymfony · symfony/ux-autocompleteEPSS 0.31%via GHSA
CVE-2026-55791Critical
3mo ago

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

▾ Midnightcraftcms · craftcms/cmsEPSS 0.46%via GHSA
GHSA-78vr-q6cf-c7p6Medium
3mo ago

Craft Commerce: Partial Payment Amount Without Lower Bound Validation

Craft Commerce: Partial Payment Amount Without Lower Bound Validation

▾ Sunlitcraftcms · craftcms/commercevia GHSA
CVE-2026-55877Medium· 6.1
3mo ago

symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses

symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses

▾ Sunlitsymfony · symfony/ux-iconsEPSS 0.34%via GHSA
CVE-2026-55878High· 7.8
3mo ago

symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest

symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest

▾ Twilightsymfony · symfony/ux-toolkitEPSS 0.19%via GHSA
CVE-2026-55744High· 8.1
3mo ago

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

▾ Twilightcotonti · cotonti/cotontiEPSS 0.20%via GHSA
CVE-2026-55742Critical· 9.6
3mo ago

Cotonti: Cross-Site Request Forgery in the administration rights handler

Cotonti: Cross-Site Request Forgery in the administration rights handler

▾ Midnightcotonti · cotonti/cotontiEPSS 0.21%via GHSA
CVE-2026-55745Medium· 5.4
3mo ago

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

▾ Sunlitcotonti · cotonti/cotontiEPSS 0.14%via GHSA
CVE-2026-55746High· 7.6
3mo ago

Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module

Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module

▾ Twilightcotonti · cotonti/cotontiEPSS 0.30%via GHSA
CVE-2026-55885Medium· 6.8
3mo ago

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

▾ Sunlitgetgrav · getgrav/gravEPSS 0.27%via GHSA
CVE-2026-55890Medium· 4.8
3mo ago

Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr

Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr

▾ Sunlitgetgrav · getgrav/gravEPSS 0.31%via GHSA
CVE-2026-49274Medium
3mo ago

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.48%via GHSA
CVE-2026-49276High
3mo ago

Kirby: Self cross-site scripting (self-XSS) in the writer field

Kirby: Self cross-site scripting (self-XSS) in the writer field

▾ Twilightgetkirby · getkirby/cmsEPSS 0.43%via GHSA
CVE-2026-50188Medium
3mo ago

Kirby: Request header injection in `Http\Remote`

Kirby: Request header injection in `Http\Remote`

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.44%via GHSA
CVE-2026-54002High
3mo ago

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

▾ Twilightgetkirby · getkirby/cmsEPSS 0.55%via GHSA
CVEs tagged “composer” — page 15 · VulnSea