VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

GHSA-fwwx-3362-3947Critical· 8.8
1mo ago

Duplicate Advisory: Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write

Duplicate Advisory: Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write

▾ Midnightgetgrav · getgrav/gravvia GHSA
GHSA-9pr6-8r9w-wvmjCritical· 8.7
1mo ago

Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

▾ Midnightgetgrav · getgrav/gravvia GHSA
GHSA-993v-76jg-67xrMedium· 5.4
1mo ago

Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate

Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate

▾ Sunlitgetgrav · getgrav/gravvia GHSA
GHSA-m97h-2qj3-5773Critical· 9.1
1mo ago

Duplicate Advisory: Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin

Duplicate Advisory: Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin

▾ Midnightgetgrav · getgrav/gravvia GHSA
GHSA-2rhw-8953-48q3High· 5.9
1mo ago

Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-q8cg-5m48-5c25Medium· 7.6
1mo ago

Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL

Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-75837Critical· 9.1
1mo ago

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-ad…

▾ Midnightgetgrav · getgrav/gravEPSS 0.49%via NVD
CVE-2026-75834Medium· 5.4
1mo ago

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 b…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.26%via NVD
CVE-2026-75831High· 7.6
1mo ago

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allo…

▾ Twilightgetgrav · getgrav/gravEPSS 0.35%via NVD
CVE-2026-75828High· 8.7
1mo ago

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like o…

▾ Twilightgetgrav · getgrav/gravEPSS 0.39%via NVD
CVE-2026-75827High· 8.8PoC
1mo ago

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config acces…

▾ Midnightgetgrav · getgrav/gravEPSS 0.86%via NVD
CVE-2026-74907Medium· 5.9
1mo ago

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling direc…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.43%via NVD
CVE-2026-55224HighPoC
1mo ago

MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

▾ Midnightmineadmin · mineadmin/mineadminvia GHSA
CVE-2026-54347High· 8.7
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content…

▾ Twilightfroxlor · froxlor/froxlorEPSS 0.42%via NVD
CVE-2026-54348High· 7.2
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.i…

▾ Twilightfroxlor · froxlor/froxlorEPSS 0.66%via NVD
CVE-2026-54543Medium· 5.4
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab char…

▾ Sunlitfroxlor · froxlor/froxlorEPSS 0.45%via NVD
CVE-2026-55593Medium· 6.5
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a v…

▾ Sunlitfroxlor · froxlor/froxlorEPSS 0.26%via NVD
CVE-2026-62988Critical· 9.0
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxl…

▾ Midnightfroxlor · froxlor/froxlorEPSS 0.63%via NVD
GHSA-jf24-8g2h-2wg7Medium
1mo ago

LibreNMS Vulnerable to Remote Code Execution via AboutController

LibreNMS Vulnerable to Remote Code Execution via AboutController

▾ Sunlitlibrenms · librenms/librenmsvia GHSA
GHSA-7cj5-v4pp-v632Medium· 4.8
1mo ago

LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users

LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users

▾ Sunlitlibrenms · librenms/librenmsvia GHSA
GHSA-7gww-x7fh-jf9jHigh· 8.1
1mo ago

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

▾ Twilightlibrenms · librenms/librenmsvia GHSA
CVE-2026-52854High· 8.6
1mo ago

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays p…

▾ Twilightmediawiki · mediawiki/mapsEPSS 0.58%via NVD
GHSA-wvxr-6v52-gfmhHigh· 8.8
1mo ago

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-cgvr-f65r-pjv3Medium· 5.4
1mo ago

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-72832Medium· 5.4
1mo ago

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which c…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.31%via NVD
CVE-2026-72819High· 8.8
1mo ago

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can byp…

▾ Twilightgetgrav · getgrav/gravEPSS 0.90%via NVD
CVE-2026-49262Low· 3.0
1mo ago

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) …

▾ Sunlitaimeos · aimeos/pagibleEPSS 0.17%via NVD
CVE-2026-69127Medium
1mo ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauth…

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.51%via NVD
CVE-2026-54164Medium· 6.5
1mo ago

API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)

API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)

▾ Sunlitapi-platform · api-platform/coreEPSS 0.34%via GHSA
GHSA-wg23-69c2-gjc8Critical
1mo ago

Craft CMS: Passkey login accepts replayed WebAuthn assertions

Craft CMS: Passkey login accepts replayed WebAuthn assertions

▾ Midnightcraftcms · craftcms/cmsvia GHSA
CVEs tagged “composer” — page 8 · VulnSea