VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

GHSA-2223-f22x-24cqMedium· 4.9
1mo ago

Winter: Local File Inclusion through =include directives in JavaScript asset compilation

Winter: Local File Inclusion through =include directives in JavaScript asset compilation

▾ Sunlitwinter · winter/wn-system-modulevia GHSA
GHSA-8cfw-pcwh-v63wHigh· 8.4
1mo ago

Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)

Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)

▾ Twilightwinter · winter/wn-system-modulevia GHSA
GHSA-7mpf-4465-7fc2Low· 2.0
1mo ago

Winter: Stored XSS through Backend List widget image columns

Winter: Stored XSS through Backend List widget image columns

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-mpmw-f6h6-3g26Medium· 4.3
1mo ago

Winter: My Account preview exposes another backend user's profile by record ID

Winter: My Account preview exposes another backend user's profile by record ID

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-fm29-4mq3-phg6Medium· 5.3
1mo ago

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-5cwr-5jxg-pcf6Medium· 4.5
1mo ago

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-p2ch-c2c3-4xm5Medium· 6.1
1mo ago

Winter: CSRF through AJAX handler names reachable as backend page actions

Winter: CSRF through AJAX handler names reachable as backend page actions

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-hq84-x37p-j6q5Medium· 4.5
1mo ago

Winter: Reflected XSS through the search query parameter in the backend Table widget

Winter: Reflected XSS through the search query parameter in the backend Table widget

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
CVE-2026-62672Medium· 6.0PoC
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to preg_replace(). Wh…

▾ Twilightgetgrav · gravEPSS 0.38%via NVD
CVE-2026-62669High· 7.4
1mo ago

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. A…

▾ Twilightgetgrav · getgrav/gravEPSS 0.50%via NVD
CVE-2026-61690Medium· 6.5
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive uncompressed-size, fi…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.53%via NVD
CVE-2026-61842Medium· 6.5
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters to serialize that …

▾ Sunlitgetgrav · getgrav/gravEPSS 0.44%via NVD
CVE-2026-64850High
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dan…

▾ Twilightgetgrav · getgrav/gravEPSS 0.47%via NVD
CVE-2026-55694High
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-…

▾ Twilightsnipe · snipe/snipe-itEPSS 0.41%via NVD
CVE-2026-55703Medium· 4.3
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Control…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.33%via NVD
CVE-2026-61807Medium
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-si…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.47%via NVD
CVE-2026-62673High
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns case-sensitively. On …

▾ Twilightgetgrav · getgrav/gravEPSS 0.54%via NVD
CVE-2026-54491High· 7.1
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a point-in-time App\Helpers\Network::isPublicHost() or isSafeUrl() check without pinning the validated address, and most…

▾ Twilightphanan · phanan/koelEPSS 0.38%via NVD
CVE-2026-54494Medium
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_var() with FILTER_FLAG_NO_PRIV_RANGE and FILTER_FLAG_NO_RES_RANGE, which treats NAT64 64:ff9b::/96 and 6to4 2002::/16 w…

▾ Sunlitphanan · phanan/koelEPSS 0.43%via NVD
CVE-2026-54492Medium· 4.3
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view route accepts an authenticated user's private URL because app/Http/Requests/Subsonic/CreatePodcastChannelRequest.php …

▾ Sunlitphanan · phanan/koelEPSS 0.41%via NVD
CVE-2026-54493High· 7.7
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl and Has…

▾ Twilightphanan · phanan/koelEPSS 0.41%via NVD
CVE-2026-52889Critical· 9.8
1mo ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Valu…

▾ Midnightverbb · verbb/formieEPSS 1.3%via NVD
CVE-2026-49283High· 8.7
1mo ago

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically vali…

▾ Twilightsimplesamlphp · simplesamlphp/saml2EPSS 0.47%via NVD
CVE-2026-49289High· 7.5
1mo ago

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages. XPath ev…

▾ Twilightsimplesamlphp · simplesamlphp/saml2EPSS 0.78%via NVD
CVE-2026-49870Medium· 5.9
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepte…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.40%via NVD
CVE-2026-49976Medium· 6.5
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. …

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.47%via NVD
CVE-2026-50550Medium· 5.8
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.27%via NVD
CVE-2026-55482Medium· 6.3
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing asse…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.33%via NVD
CVE-2026-55483Medium
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.41%via NVD
CVE-2026-55519Medium· 5.4
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in …

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.37%via NVD
CVEs tagged “composer” — page 7 · VulnSea