Tagged “composer”
CVEs tagged composer, newest first.
504 CVEsRSS
CVE-2026-62992MediumSmarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating…
CVE-2026-62996MediumSmarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers an…
GHSA-xxpx-f366-4xpqMediumCraft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
GHSA-p8x7-9vfw-p7vcHighCraft CMS: Arbitrary user password reset leading to administrator account takeover
Craft CMS: Arbitrary user password reset leading to administrator account takeover
CVE-2026-67434High· 7.8PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgbl…
GHSA-2rp4-x2j7-qmccMediumCraft CMS: Stored XSS in the control panel via unescaped draft name
Craft CMS: Stored XSS in the control panel via unescaped draft name
GHSA-7hxc-f267-h5q7LowCraft CMS: Incorrect path validation could potentially lead to path traversal
Craft CMS: Incorrect path validation could potentially lead to path traversal
GHSA-rvmm-v933-jgxqMediumCraft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
GHSA-596p-6jv8-775vMediumCraft CMS: Authenticated leak of secret environment variables
Craft CMS: Authenticated leak of secret environment variables
GHSA-957r-qf9p-67xwMediumCraft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
CVE-2026-54717Medium· 5.4Silverstripe CMS is an open source content management system
Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb t…
CVE-2026-71478Medium· 6.1league/commonmark is a PHP library for parsing and rendering CommonMark Markdown
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage retur…
CVE-2026-71488High· 7.5league/commonmark is a PHP library for parsing and rendering CommonMark Markdown
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing pa…
GHSA-g2gp-3wwq-f4phHigh· 7.5league/commonmark: Denial of service via adjacent inline attribute blocks
league/commonmark: Denial of service via adjacent inline attribute blocks
GHSA-jfm3-95jq-q3rfHigh· 7.5league/commonmark: Denial of service via duplicate footnote definitions
league/commonmark: Denial of service via duplicate footnote definitions
GHSA-mh25-x5hq-wrqpHigh· 7.5league/commonmark: Denial of service via colliding heading slugs
league/commonmark: Denial of service via colliding heading slugs
GHSA-mj63-m3rc-8pprMedium· 5.3league/commonmark: Denial of service via deeply nested XML output
league/commonmark: Denial of service via deeply nested XML output
GHSA-265m-7826-wjqmHighCraft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
CVE-2026-14793Medium· 4.3Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
GHSA-f5wm-88jv-g5hxHighCraft CMS: Authenticated RCE through Twig sandbox escape
Craft CMS: Authenticated RCE through Twig sandbox escape
CVE-2026-64664Medium· 4.3Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belo…
CVE-2026-64665High· 8.1Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…
CVE-2026-64663Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templa…
CVE-2026-64662Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and cust…
CVE-2026-71434Medium· 5.3Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could up…
CVE-2026-71435Medium· 6.1Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submit…
GHSA-vj8j-973f-r65jHigh· 8.1Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
GHSA-mmwh-j75q-gxp8High· 7.5Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
CVE-2026-69245Medium· 6.5Guzzle is an extensible PHP HTTP client
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…
CVE-2026-69246High· 7.2Guzzle is an extensible PHP HTTP client
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that H…