VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

CVE-2026-47346High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.44%via GHSA
CVE-2026-47350Medium
3mo ago

TYPO3 CMS has Broken Access Control in its DataHandler

TYPO3 CMS has Broken Access Control in its DataHandler

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-49741High
3mo ago

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.37%via GHSA
CVE-2026-47345Medium
3mo ago

TYPO3 HTML Sanitizer allows Cross-site Scripting

TYPO3 HTML Sanitizer allows Cross-site Scripting

▾ Sunlittypo3 · typo3/html-sanitizerEPSS 0.44%via GHSA
CVE-2026-47343High
3mo ago

TYPO3 CMS: Destructive Actions on File Mount Folders

TYPO3 CMS: Destructive Actions on File Mount Folders

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-47347Medium
3mo ago

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.48%via GHSA
CVE-2026-47349Medium
3mo ago

TYPO3 CMS has Broken Access Control in the Recycler Module

TYPO3 CMS has Broken Access Control in the Recycler Module

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-11607High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-49214Medium· 5.3
3mo ago

guzzlehttp/psr7 has CRLF Injection via URI Host Component

guzzlehttp/psr7 has CRLF Injection via URI Host Component

▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.31%via GHSA
CVE-2026-48998Medium· 5.3
3mo ago

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.31%via GHSA
CVE-2026-53723Medium· 5.8
3mo ago

guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator

guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator

▾ Sunlitguzzlehttp · guzzlehttp/guzzle-servicesEPSS 0.35%via GHSA
CVE-2026-48062Critical· 9.8
3mo ago

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

▾ Midnightcodeigniter4 · codeigniter4/frameworkEPSS 0.78%via GHSA
CVE-2026-48067Medium· 6.5
3mo ago

Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields

Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields

▾ Sunlitfilament · filament/tablesEPSS 0.30%via GHSA
CVE-2026-47767Medium
3mo ago

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

▾ Sunlitsymfony · symfony/runtimeEPSS 0.72%via GHSA
CVE-2026-48030Critical· 9.9PoC
3mo ago

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

▾ Abyssalpheditor · pheditor/pheditorEPSS 7.5%via GHSA
CVE-2026-45034CriticalPoC
3mo ago

PHPSpreadsheet has a patch bypass for CVE-2026-34084

PHPSpreadsheet has a patch bypass for CVE-2026-34084

▾ Abyssalphpoffice · phpoffice/phpspreadsheetEPSS 0.46%via GHSA
CVE-2026-47693Medium· 6.9
3mo ago

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

▾ Sunlitpoweradmin · poweradmin/poweradminEPSS 0.38%via GHSA
CVE-2026-56701Medium· 6.5
4mo ago

Grav is Vulnerable to XXE via SVG Upload

Grav is Vulnerable to XXE via SVG Upload

▾ Sunlitgetgrav · getgrav/gravEPSS 0.40%via GHSA
CVE-2026-56341High· 7.5
6mo ago

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideoEPSS 0.46%via GHSA
CVE-2026-56346Medium
6mo ago

AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

▾ Sunlitwwbn · wwbn/avideoEPSS 0.61%via GHSA
CVE-2026-31887High
6mo ago

Shopware: Unauthenticated data extraction possible through store-api.order endpoint

Shopware: Unauthenticated data extraction possible through store-api.order endpoint

▾ Twilightshopware · shopware/coreEPSS 0.39%via GHSA
CVE-2025-69277Medium· 4.5
9mo ago

libsodium has Incomplete List of Disallowed Inputs

libsodium has Incomplete List of Disallowed Inputs

▾ Sunlitparagonie · paragonie/sodium_compatEPSS 0.18%via OSV
CVE-2025-58048Critical· 9.9
1y ago

Paymenter is a free and open-source webshop solution for hostings

Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files. This could result in sensitive…

▾ Midnightpaymenter · paymenter/paymenterEPSS 0.41%via NVD
CVE-2022-23064High· 8.8
4y ago

snipe-IT vulnerable to host header injection

snipe-IT vulnerable to host header injection

▾ Twilightsnipe · snipe/snipe-itEPSS 1.3%via GHSA
CVEs tagged “composer” — page 17 · VulnSea