VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

CVE-2026-52823Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing o…

▾ Sunlitkimai · kimaiEPSS 0.30%via NVD
CVE-2026-52824Critical· 9.1PoC
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that …

▾ Abyssalkimai · kimaiEPSS 1.3%via NVD
CVE-2026-52825Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the ref…

▾ Sunlitkimai · kimaiEPSS 0.45%via NVD
CVE-2026-52826Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the author…

▾ Sunlitkimai · kimaiEPSS 0.43%via NVD
CVE-2026-55374Medium· 4.8
1w ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual path segments, including the sch…

▾ Sunlitjleehr · canto-saas-apiEPSS 0.36%via NVD
CVE-2026-55375Medium· 5.3
1w ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing …

▾ Sunlitjleehr · canto-saas-apiEPSS 0.38%via NVD
CVE-2026-55690High· 7.5
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes…

▾ TwilightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.49%via NVD
CVE-2026-55691High· 8.6PoC
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/Embed…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.48%via NVD
CVE-2026-55692High· 7.5PoC
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.49%via NVD
GHSA-2xmm-m4wv-3fjhLow· 3.9
1w ago

October CMS: Incomplete Scheme Validation in Image Resizer

October CMS: Incomplete Scheme Validation in Image Resizer

▾ Sunlitoctober · october/octobervia GHSA
CVE-2026-49400Low· 3.3
1w ago

October System provides the system module for October Content Management System

October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state as `base64(serialize(...))` and consumed it with `unserial…

▾ Sunlitoctobercms · octoberEPSS 0.24%via NVD
CVE-2026-46696Low· 3.3
1w ago

October System provides the system module for October Content Management System

October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. …

▾ Sunlitoctobercms · systemEPSS 0.27%via NVD
CVE-2026-55416High· 8.8
1w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and group…

▾ Twilightpimcore · pimcoreEPSS 0.65%via NVD
CVE-2026-54175High· 7.6
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.55%via NVD
CVE-2026-54176Medium· 6.5
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccount…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.65%via NVD
CVE-2026-54177Medium· 6.6
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, HasUploadFields methods uploadFi…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.93%via NVD
CVE-2026-54178High· 8.1
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDi…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.56%via NVD
CVE-2026-54180High· 7.6
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder …

▾ TwilightLaravel-Backpack · CRUDEPSS 0.46%via NVD
CVE-2026-54181Medium· 5.4
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.31%via NVD
CVE-2026-54182High· 8.1
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::mak…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.78%via NVD
CVE-2026-57570Medium· 6.5
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.15 and 7.0.47, HasMany and MorphMany handling t…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.44%via NVD
CVE-2026-55072High· 8.5PoC
1w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/Dat…

▾ Midnightpimcore · pimcoreEPSS 0.41%via NVD
CVE-2026-54087High· 7.6
1w ago

EasyAdmin is a fast and modern admin generator for Symfony applications

EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline s…

▾ TwilightEasyCorp · EasyAdminBundleEPSS 0.40%via NVD
CVE-2026-50157Medium· 6.5
1w ago

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bear…

▾ Sunlitauth0 · symfonyEPSS 0.51%via NVD
CVE-2026-55795Medium· 6.9
1w ago

Craft Commerce is an ecommerce platform for Craft CMS

Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when the number POST or GET parameter is supplied. An unauthent…

▾ Sunlitcraftcms · commerceEPSS 0.51%via NVD
CVE-2026-56828High· 8.8
2w ago

Shopper: privilege escalation via improper Livewire admin component authorization

Shopper: privilege escalation via improper Livewire admin component authorization

▾ Twilightshopper · shopper/frameworkvia GHSA
CVE-2026-56826Medium· 5.4
2w ago

Shopping privilege escalation through missing authorization in Settings components

Shopping privilege escalation through missing authorization in Settings components

▾ Sunlitshopper · shopper/frameworkvia GHSA
CVE-2026-49992Medium· 6.3
2w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exp…

▾ Sunlitkimai · kimaiEPSS 0.22%via NVD
CVE-2026-49865Medium· 5.3PoC
2w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is lat…

▾ Twilightkimai · kimaiEPSS 0.35%via NVD
CVE-2026-47156Critical· 9.3
2w ago

MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator

MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowi…

▾ Midnightmantisbt · mantisbtEPSS 0.69%via CVEORG
CVEs tagged “composer” — page 3 · VulnSea