VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

CVE-2026-82395Medium
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media …

▾ Sunlitsulu · sulu/suluEPSS 0.43%via NVD
CVE-2026-82394Medium
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforc…

▾ Sunlitsulu · sulu/suluEPSS 0.58%via NVD
CVE-2026-82396Medium· 5.4
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and it…

▾ Sunlitsulu · sulu/suluEPSS 0.30%via NVD
CVE-2026-81890Medium· 5.4
3w ago

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken(…

▾ Sunlitstudio-42 · studio-42/elfinderEPSS 0.18%via NVD
CVE-2026-81891High· 8.1
3w ago

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeType…

▾ TwilightStudio-42 · Studio-42/elFinderEPSS 0.90%via NVD
CVE-2026-81887Medium
3w ago

Livewire is a full-stack framework for Laravel

Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __p…

▾ Sunlitlivewire · livewire/livewireEPSS 0.68%via NVD
CVE-2026-81892High· 8.1
3w ago

EasyAdmin is a fast and modern admin generator for Symfony applications

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuIt…

▾ Twilighteasycorp · easycorp/easyadmin-bundleEPSS 0.45%via NVD
CVE-2026-62993Medium· 8.6
3w ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and…

▾ Sunlitsmarty · smarty/smartyEPSS 0.57%via NVD
CVE-2026-75594High
3w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated pare…

▾ Twilightgetkirby · getkirby/cmsEPSS 0.76%via NVD
CVE-2026-71415High
3w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Ap…

▾ Twilightgetkirby · getkirby/cmsEPSS 0.43%via NVD
CVE-2026-81889High· 8.6
3w ago

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable becau…

▾ Twilightstudio-42 · studio-42/elfinderEPSS 0.55%via NVD
CVE-2026-15305Medium
3w ago

TYPO3 CMS - Unrestricted File Upload in Form Framework

TYPO3 CMS - Unrestricted File Upload in Form Framework

▾ Sunlittypo3 · typo3/cms-formEPSS 0.25%via GHSA
CVE-2026-54179Medium· 4.4
3w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/Library/Uploaders/Si…

▾ Sunlitbackpack · backpack/crudEPSS 0.26%via NVD
CVE-2026-55843High· 6.5
1mo ago

Snipe-IT has an Improper Privilege Management issue

Snipe-IT has an Improper Privilege Management issue

▾ Twilightsnipe · snipe/snipe-itEPSS 0.54%via GHSA
CVE-2026-55779Medium· 5.4
1mo ago

Silverstripe Versioned provides versioning for Silverstripe models

Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Ti…

▾ Sunlitsilverstripe · silverstripe/versionedEPSS 0.34%via NVD
CVE-2026-55891Low· 0.0
1mo ago

PrivateBin is an online pastebin where the server has zero knowledge of pasted data

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation …

▾ Sunlitprivatebin · privatebin/privatebinEPSS 0.54%via NVD
CVE-2026-55696Medium· 4.3
1mo ago

PrivateBin is an online pastebin where the server has zero knowledge of pasted data

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled MIME types and uses getBlobU…

▾ Sunlitprivatebin · privatebin/privatebinEPSS 0.37%via NVD
CVE-2026-55584High· 7.5PoC
1mo ago

phpSysInfo is a customizable PHP script that displays system information

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A…

▾ Midnightphpsysinfo · phpsysinfo/phpsysinfoEPSS 1.9%via NVD
CVE-2026-55207High· 8.8
1mo ago

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

▾ Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.67%via GHSA
CVE-2026-55208High· 7.7
1mo ago

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

▾ Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.41%via GHSA
CVE-2026-55220Critical
1mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspot…

▾ Midnightpimcore · pimcore/pimcoreEPSS 0.68%via NVD
CVE-2026-55634Critical· 9.9
1mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…

▾ Midnightpimcore · pimcore/pimcoreEPSS 0.65%via NVD
CVE-2026-55460High· 7.1
1mo ago

Snipe-IT has an authorization bypass on bulk editing users

Snipe-IT has an authorization bypass on bulk editing users

▾ Twilightsnipe · snipe/snipe-itEPSS 0.44%via GHSA
CVE-2026-55464Medium· 5.4
1mo ago

Snipe-IT vulnerable to stored XSS via Markdown custom field

Snipe-IT vulnerable to stored XSS via Markdown custom field

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.29%via GHSA
CVE-2026-55472Medium· 4.3
1mo ago

Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.33%via GHSA
CVE-2026-55476Medium
1mo ago

Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter

Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.34%via GHSA
CVE-2026-55516High· 7.7
1mo ago

Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

▾ Twilightsnipe · snipe/snipe-itEPSS 0.38%via GHSA
CVE-2026-54718High· 7.2
1mo ago

Silverstripe Advanced Workflow is a highly configurable step-based workflow module

Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side te…

▾ Twilightsymbiote · symbiote/silverstripe-advancedworkflowEPSS 1.0%via NVD
CVE-2026-54720Medium· 5.4
1mo ago

Silverstripe Framework: Possible XSS attack through media embed

Silverstripe Framework: Possible XSS attack through media embed

▾ Sunlitsilverstripe · silverstripe/frameworkEPSS 0.26%via GHSA
CVE-2026-54721High· 8.8
1mo ago

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted a…

▾ Twilightsilverstripe · silverstripe/userformsEPSS 0.73%via NVD
CVEs tagged “composer” — page 5 · VulnSea