Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
GHSA-fwwx-3362-3947Critical· 8.8Duplicate Advisory: Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write
Duplicate Advisory: Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write
GHSA-9pr6-8r9w-wvmjCritical· 8.7Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
GHSA-993v-76jg-67xrMedium· 5.4Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
GHSA-m97h-2qj3-5773Critical· 9.1Duplicate Advisory: Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
Duplicate Advisory: Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
GHSA-2rhw-8953-48q3High· 5.9Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
GHSA-q8cg-5m48-5c25Medium· 7.6Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL
Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL
CVE-2026-75837Critical· 9.1Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-ad…
CVE-2026-75834Medium· 5.4Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)
Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 b…
CVE-2026-75831High· 7.6Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allo…
CVE-2026-75828High· 8.7Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like o…
CVE-2026-75827High· 8.8PoCGrav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config acces…
CVE-2026-74907Medium· 5.9Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation
Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling direc…
CVE-2026-55224HighPoCMineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
CVE-2026-54347High· 8.7Froxlor is open source server administration software
Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content…
CVE-2026-54348High· 7.2Froxlor is open source server administration software
Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.i…
CVE-2026-54543Medium· 5.4Froxlor is open source server administration software
Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab char…
CVE-2026-55593Medium· 6.5Froxlor is open source server administration software
Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a v…
CVE-2026-62988Critical· 9.0Froxlor is open source server administration software
Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxl…
GHSA-jf24-8g2h-2wg7MediumLibreNMS Vulnerable to Remote Code Execution via AboutController
LibreNMS Vulnerable to Remote Code Execution via AboutController
GHSA-7cj5-v4pp-v632Medium· 4.8LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users
LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users
GHSA-7gww-x7fh-jf9jHigh· 8.1LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
CVE-2026-52854High· 8.6Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays p…
GHSA-wvxr-6v52-gfmhHigh· 8.8Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS
Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS
GHSA-cgvr-f65r-pjv3Medium· 5.4Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss
Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss
CVE-2026-72832Medium· 5.4Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)
Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which c…
CVE-2026-72819High· 8.8Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can byp…
CVE-2026-49262Low· 3.0In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding
In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) …
CVE-2026-69127MediumKirby is an open-source content management system
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauth…
CVE-2026-54164Medium· 6.5API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
GHSA-wg23-69c2-gjc8CriticalCraft CMS: Passkey login accepts replayed WebAuthn assertions
Craft CMS: Passkey login accepts replayed WebAuthn assertions