Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
CVE-2026-33731Medium· 6.5AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
CVE-2026-44583Medium· 5.3Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module
Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module
CVE-2026-44584Medium· 4.3Paymenter doesn't reset email verification status after email change
Paymenter doesn't reset email verification status after email change
CVE-2026-44585Medium· 5.4Paymenter has broken object level authorization via service reference manipulation on ticket creation
Paymenter has broken object level authorization via service reference manipulation on ticket creation
GHSA-xj9w-cgqg-q897Medium· 6.5Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
GHSA-rg7q-4223-phjwHigh· 7.5Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
CVE-2026-55568Medium· 5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVE-2026-55766Medium· 4.8guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
CVE-2026-55767Medium· 5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
CVE-2026-49208Mediumux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
CVE-2026-49209Lowsymfony/ux-live-component: Denial of service via unbounded batch action requests
symfony/ux-live-component: Denial of service via unbounded batch action requests
CVE-2026-49210Mediumsymfony/ux-live-component: XSS via attacker-controlled child component tag
symfony/ux-live-component: XSS via attacker-controlled child component tag
CVE-2026-49211Mediumsymfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
CVE-2026-49212Lowsymfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
CVE-2026-49215Lowsymfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
CVE-2026-49216Mediumsymfony/ux-autocomplete: XSS via unescaped AJAX response data
symfony/ux-autocomplete: XSS via unescaped AJAX response data
CVE-2026-55791CriticalCraft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
GHSA-78vr-q6cf-c7p6MediumCraft Commerce: Partial Payment Amount Without Lower Bound Validation
Craft Commerce: Partial Payment Amount Without Lower Bound Validation
CVE-2026-55877Medium· 6.1symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses
symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses
CVE-2026-55878High· 7.8symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
CVE-2026-55744High· 8.1Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
CVE-2026-55742Critical· 9.6Cotonti: Cross-Site Request Forgery in the administration rights handler
Cotonti: Cross-Site Request Forgery in the administration rights handler
CVE-2026-55745Medium· 5.4Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
CVE-2026-55746High· 7.6Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
CVE-2026-55885Medium· 6.8Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
CVE-2026-55890Medium· 4.8Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
CVE-2026-49274MediumKirby: `pages.access` permission is not checked in the pages picker for parent pages
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
CVE-2026-49276HighKirby: Self cross-site scripting (self-XSS) in the writer field
Kirby: Self cross-site scripting (self-XSS) in the writer field
CVE-2026-50188MediumKirby: Request header injection in `Http\Remote`
Kirby: Request header injection in `Http\Remote`
CVE-2026-54002HighKirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`