Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
CVE-2026-82395MediumSulu is an open-source PHP content management system based on the Symfony framework
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media …
CVE-2026-82394MediumSulu is an open-source PHP content management system based on the Symfony framework
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforc…
CVE-2026-82396Medium· 5.4Sulu is an open-source PHP content management system based on the Symfony framework
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and it…
CVE-2026-81890Medium· 5.4elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken(…
CVE-2026-81891High· 8.1elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeType…
CVE-2026-81887MediumLivewire is a full-stack framework for Laravel
Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __p…
CVE-2026-81892High· 8.1EasyAdmin is a fast and modern admin generator for Symfony applications
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuIt…
CVE-2026-62993Medium· 8.6Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and…
CVE-2026-75594HighKirby is an open-source content management system
Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated pare…
CVE-2026-71415HighKirby is an open-source content management system
Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Ap…
CVE-2026-81889High· 8.6elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable becau…
CVE-2026-15305MediumTYPO3 CMS - Unrestricted File Upload in Form Framework
TYPO3 CMS - Unrestricted File Upload in Form Framework
CVE-2026-54179Medium· 4.4backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/Library/Uploaders/Si…
CVE-2026-55843High· 6.5Snipe-IT has an Improper Privilege Management issue
Snipe-IT has an Improper Privilege Management issue
CVE-2026-55779Medium· 5.4Silverstripe Versioned provides versioning for Silverstripe models
Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Ti…
CVE-2026-55891Low· 0.0PrivateBin is an online pastebin where the server has zero knowledge of pasted data
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation …
CVE-2026-55696Medium· 4.3PrivateBin is an online pastebin where the server has zero knowledge of pasted data
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled MIME types and uses getBlobU…
CVE-2026-55584High· 7.5PoCphpSysInfo is a customizable PHP script that displays system information
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A…
CVE-2026-55207High· 8.8Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
CVE-2026-55208High· 7.7Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
CVE-2026-55220CriticalPimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspot…
CVE-2026-55634Critical· 9.9Pimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…
CVE-2026-55460High· 7.1Snipe-IT has an authorization bypass on bulk editing users
Snipe-IT has an authorization bypass on bulk editing users
CVE-2026-55464Medium· 5.4Snipe-IT vulnerable to stored XSS via Markdown custom field
Snipe-IT vulnerable to stored XSS via Markdown custom field
CVE-2026-55472Medium· 4.3Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
CVE-2026-55476MediumSnipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
CVE-2026-55516High· 7.7Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
CVE-2026-54718High· 7.2Silverstripe Advanced Workflow is a highly configurable step-based workflow module
Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side te…
CVE-2026-54720Medium· 5.4Silverstripe Framework: Possible XSS attack through media embed
Silverstripe Framework: Possible XSS attack through media embed
CVE-2026-54721High· 8.8Silverstripe UserForms provides a visual form builder for the Silverstripe CMS
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted a…