VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

CVE-2026-54004Medium
3mo ago

Kirby: Access to files of top-level drafts is not protected by permissions

Kirby: Access to files of top-level drafts is not protected by permissions

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.50%via GHSA
CVE-2026-54003Critical
3mo ago

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

▾ Midnightgetkirby · getkirby/cmsEPSS 0.74%via GHSA
CVE-2026-54005High
3mo ago

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

▾ Twilightgetkirby · getkirby/cmsEPSS 0.43%via GHSA
GHSA-g7m4-839x-ch6vHigh
3mo ago

spomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation

spomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation

▾ Twilightspomky-labs · spomky-labs/otphpvia GHSA
GHSA-2jx3-65f3-xr8rMedium
3mo ago

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError

▾ Sunlitspomky-labs · spomky-labs/otphpvia GHSA
GHSA-6vvh-pxr4-25r7Medium
3mo ago

PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption

PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption

▾ Sunlitweb-token · web-token/jwt-experimentalvia GHSA
GHSA-3prj-6hqw-cm82High
3mo ago

PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service

PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service

▾ Twilightweb-token · web-token/jwt-libraryvia GHSA
GHSA-jc38-x7x8-2xc8High
3mo ago

PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks

PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks

▾ Twilightweb-token · web-token/jwt-frameworkvia GHSA
GHSA-5739-39v2-5754Medium
3mo ago

PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle

PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle

▾ Sunlitweb-token · web-token/jwt-libraryvia GHSA
GHSA-5vg9-5847-vvmqHigh· 8.9
3mo ago

Laravel Framework: CRLF injection in default email rule

Laravel Framework: CRLF injection in default email rule

▾ Twilightlaravel · laravel/frameworkvia GHSA
GHSA-crmm-hgp2-wgrpMedium· 4.2
3mo ago

Laravel Framework: Temporary Signed URL Path Confusion

Laravel Framework: Temporary Signed URL Path Confusion

▾ Sunlitlaravel · laravel/frameworkvia GHSA
CVE-2026-55409High· 7.6
3mo ago

Filament: Disabled RichEditor field state can be used for XSS

Filament: Disabled RichEditor field state can be used for XSS

▾ Twilightfilament · filament/formsEPSS 0.28%via GHSA
CVE-2026-55590Medium
3mo ago

CakePHP Authentication: Open redirect weakness via backslash bypass

CakePHP Authentication: Open redirect weakness via backslash bypass

▾ Sunlitcakephp · cakephp/authenticationEPSS 0.49%via GHSA
CVE-2026-11407High· 7.2
3mo ago

Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed

Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed

▾ Twilightpimcore · pimcore/pimcoreEPSS 0.62%via GHSA
GHSA-m557-wrgg-6rp4Medium· 5.8
3mo ago

phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access

phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access

▾ Sunlitphpseclib · phpseclib/phpseclibvia GHSA
CVE-2026-48761Medium
3mo ago

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes

▾ Sunlitsymfony · symfony/html-sanitizerEPSS 0.34%via GHSA
CVE-2026-48489High
3mo ago

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

▾ Twilightsymfony · symfony/security-httpEPSS 0.60%via GHSA
CVE-2026-48736Medium
3mo ago

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

▾ Sunlitsymfony · symfony/http-clientEPSS 0.57%via GHSA
CVE-2026-48747Medium
3mo ago

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

▾ Sunlitsymfony · symfony/mailomat-mailerEPSS 0.25%via GHSA
CVE-2026-48760Medium
3mo ago

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

▾ Sunlitsymfony · symfony/html-sanitizerEPSS 0.34%via GHSA
CVE-2026-48784Medium
3mo ago

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization

▾ Sunlitsymfony · symfony/routingEPSS 0.35%via GHSA
CVE-2026-54133Critical· 9.8
3mo ago

jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)

A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…

▾ MidnightRed Hat · mtdowling/jmespath.phpEPSS 0.56%via CSAF
GHSA-6jq6-x4cx-qvcmMedium
3mo ago

Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)

Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)

▾ Sunlitgrumpydictator · grumpydictator/firefly-iiivia GHSA
CVE-2026-47344Low
3mo ago

TYPO3 HTML Sanitizer allows Cross-site Scripting

TYPO3 HTML Sanitizer allows Cross-site Scripting

▾ Sunlittypo3 · typo3/html-sanitizerEPSS 0.44%via GHSA
CVE-2026-47348Medium
3mo ago

TYPO3 CMS has Cross-Site Scripting in Indexed Search

TYPO3 CMS has Cross-Site Scripting in Indexed Search

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.47%via GHSA
CVE-2026-47351Medium
3mo ago

TYPO3 CMS: Broken Access Control in Media Module

TYPO3 CMS: Broken Access Control in Media Module

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-47352Medium
3mo ago

TYPO3 CMS has Broken Access Control in Backend API

TYPO3 CMS has Broken Access Control in Backend API

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-49738Low
3mo ago

TYPO3 CMS has Broken Access Control in its File Abstraction Layer

TYPO3 CMS has Broken Access Control in its File Abstraction Layer

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.52%via GHSA
CVE-2026-49740Medium
3mo ago

TYPO3 CMS has Insecure Deserialization via Core API

TYPO3 CMS has Insecure Deserialization via Core API

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.59%via GHSA
CVE-2026-49742High
3mo ago

TYPO3 CMS has Broken Access Control in its Media Module

TYPO3 CMS has Broken Access Control in its Media Module

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.46%via GHSA
CVEs tagged “composer” — page 16 · VulnSea