VulnSea

Tagged “composer”

CVEs tagged composer, newest first.

504 CVEsRSS

CVE-2026-62992Medium
1mo ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating…

▾ Sunlitsmarty · smarty/smartyEPSS 0.53%via NVD
CVE-2026-62996Medium
1mo ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers an…

▾ Sunlitsmarty · smarty/smartyEPSS 0.51%via NVD
GHSA-xxpx-f366-4xpqMedium
1mo ago

Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element

Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-p8x7-9vfw-p7vcHigh
1mo ago

Craft CMS: Arbitrary user password reset leading to administrator account takeover

Craft CMS: Arbitrary user password reset leading to administrator account takeover

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-67434High· 7.8
1mo ago

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgbl…

▾ TwilightRed Hat · squizlabs/php_codesnifferEPSS 1.1%via NVD
GHSA-2rp4-x2j7-qmccMedium
1mo ago

Craft CMS: Stored XSS in the control panel via unescaped draft name

Craft CMS: Stored XSS in the control panel via unescaped draft name

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-7hxc-f267-h5q7Low
1mo ago

Craft CMS: Incorrect path validation could potentially lead to path traversal

Craft CMS: Incorrect path validation could potentially lead to path traversal

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-rvmm-v933-jgxqMedium
1mo ago

Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics

Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-596p-6jv8-775vMedium
1mo ago

Craft CMS: Authenticated leak of secret environment variables

Craft CMS: Authenticated leak of secret environment variables

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-957r-qf9p-67xwMedium
1mo ago

Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-54717Medium· 5.4
1mo ago

Silverstripe CMS is an open source content management system

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb t…

▾ Sunlitsilverstripe · silverstripe/cmsEPSS 0.34%via NVD
CVE-2026-71478Medium· 6.1
1mo ago

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage retur…

▾ Sunlitleague · league/commonmarkEPSS 0.36%via NVD
CVE-2026-71488High· 7.5
1mo ago

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing pa…

▾ Twilightleague · league/commonmarkEPSS 0.63%via NVD
GHSA-g2gp-3wwq-f4phHigh· 7.5
1mo ago

league/commonmark: Denial of service via adjacent inline attribute blocks

league/commonmark: Denial of service via adjacent inline attribute blocks

▾ Twilightleague · league/commonmarkvia GHSA
GHSA-jfm3-95jq-q3rfHigh· 7.5
1mo ago

league/commonmark: Denial of service via duplicate footnote definitions

league/commonmark: Denial of service via duplicate footnote definitions

▾ Twilightleague · league/commonmarkvia GHSA
GHSA-mh25-x5hq-wrqpHigh· 7.5
1mo ago

league/commonmark: Denial of service via colliding heading slugs

league/commonmark: Denial of service via colliding heading slugs

▾ Twilightleague · league/commonmarkvia GHSA
GHSA-mj63-m3rc-8pprMedium· 5.3
1mo ago

league/commonmark: Denial of service via deeply nested XML output

league/commonmark: Denial of service via deeply nested XML output

▾ Sunlitleague · league/commonmarkvia GHSA
GHSA-265m-7826-wjqmHigh
1mo ago

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-14793Medium· 4.3
1mo ago

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.39%via GHSA
GHSA-f5wm-88jv-g5hxHigh
1mo ago

Craft CMS: Authenticated RCE through Twig sandbox escape

Craft CMS: Authenticated RCE through Twig sandbox escape

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-64664Medium· 4.3
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belo…

▾ Sunlitstatamic · statamic/cmsEPSS 0.34%via NVD
CVE-2026-64665High· 8.1
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…

▾ Twilightstatamic · statamic/cmsEPSS 0.54%via NVD
CVE-2026-64663Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templa…

▾ Sunlitstatamic · statamic/cmsEPSS 0.40%via NVD
CVE-2026-64662Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and cust…

▾ Sunlitstatamic · statamic/cmsEPSS 0.41%via NVD
CVE-2026-71434Medium· 5.3
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could up…

▾ Sunlitstatamic · statamic/cmsEPSS 0.41%via NVD
CVE-2026-71435Medium· 6.1
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submit…

▾ Sunlitstatamic · statamic/cmsEPSS 0.34%via NVD
GHSA-vj8j-973f-r65jHigh· 8.1
1mo ago

Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-mmwh-j75q-gxp8High· 7.5
1mo ago

Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-69245Medium· 6.5
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…

▾ Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.20%via NVD
CVE-2026-69246High· 7.2
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that H…

▾ Twilightguzzlehttp · guzzlehttp/guzzleEPSS 0.37%via NVD
CVEs tagged “composer” — page 9 · VulnSea