Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
CVE-2026-47346HighTYPO3 CMS has Broken Access Control in its Form Framework
TYPO3 CMS has Broken Access Control in its Form Framework
CVE-2026-47350MediumTYPO3 CMS has Broken Access Control in its DataHandler
TYPO3 CMS has Broken Access Control in its DataHandler
CVE-2026-49741HighTYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
CVE-2026-47345MediumTYPO3 HTML Sanitizer allows Cross-site Scripting
TYPO3 HTML Sanitizer allows Cross-site Scripting
CVE-2026-47343HighTYPO3 CMS: Destructive Actions on File Mount Folders
TYPO3 CMS: Destructive Actions on File Mount Folders
CVE-2026-47347MediumTYPO3 CMS has an Open Redirect Vulnerability via Core Utilities
TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities
CVE-2026-47349MediumTYPO3 CMS has Broken Access Control in the Recycler Module
TYPO3 CMS has Broken Access Control in the Recycler Module
CVE-2026-11607HighTYPO3 CMS has Broken Access Control in its Form Framework
TYPO3 CMS has Broken Access Control in its Form Framework
CVE-2026-49214Medium· 5.3guzzlehttp/psr7 has CRLF Injection via URI Host Component
guzzlehttp/psr7 has CRLF Injection via URI Host Component
CVE-2026-48998Medium· 5.3guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
CVE-2026-53723Medium· 5.8guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
CVE-2026-48062Critical· 9.8CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule
CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule
CVE-2026-48067Medium· 6.5Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
CVE-2026-47767MediumSymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
CVE-2026-48030Critical· 9.9PoCPheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
CVE-2026-45034CriticalPoCPHPSpreadsheet has a patch bypass for CVE-2026-34084
PHPSpreadsheet has a patch bypass for CVE-2026-34084
CVE-2026-47693Medium· 6.9Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications
Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications
CVE-2026-56701Medium· 6.5Grav is Vulnerable to XXE via SVG Upload
Grav is Vulnerable to XXE via SVG Upload
CVE-2026-56341High· 7.5AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
CVE-2026-56346MediumAVideo has Unauthenticated PGP Message Decryption via Public Endpoint
AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
CVE-2026-31887HighShopware: Unauthenticated data extraction possible through store-api.order endpoint
Shopware: Unauthenticated data extraction possible through store-api.order endpoint
CVE-2025-69277Medium· 4.5libsodium has Incomplete List of Disallowed Inputs
libsodium has Incomplete List of Disallowed Inputs
CVE-2025-58048Critical· 9.9Paymenter is a free and open-source webshop solution for hostings
Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files. This could result in sensitive…
CVE-2022-23064High· 8.8snipe-IT vulnerable to host header injection
snipe-IT vulnerable to host header injection