Vendor Intelligence
composer
69 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.
CVE-2026-42611 · CVSS 8.9
Grav is Vulnerable to Stored XSS via Tag Injection
View CVE report →
CVE-2026-24425 · CVSS 8.8
Twig: Possible sandbox bypass when using a source policy
View CVE report →
CVE-2026-41235 · CVSS 8.8
Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement
View CVE report →
CVE-2026-42605 · CVSS 8.8
AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload
View CVE report →
CVE-2026-42843 · CVSS 8.8
Grav API Privilege Escalation to Super Admin
View CVE report →
CVE-2026-44521 · CVSS 8.8
elFinder MySQL has a SQL Injection in its Volume Driver (elFinderVolumeMySQL)
View CVE report →
CVE-2026-44741 · CVSS 8.8
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
View CVE report →
CVE-2026-45578 · CVSS 8.8
AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL
View CVE report →
CVE-2026-52775 · CVSS 8.8
YesWiki has Authenticated SQL Injection via ReactionManager
View CVE report →
CVE-2026-41147 · CVSS 8.7
NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request class
View CVE report →
CVE-2026-45270 · CVSS 8.7
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
View CVE report →
CVE-2026-47743 · CVSS 8.7
Shopper: Multiple data integrity and disclosure issues in admin Livewire components
View CVE report →
CVE-2026-49259 · CVSS 8.7
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
View CVE report →
CVE-2026-49283 · CVSS 8.7
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
View CVE report →
CVE-2026-54064 · CVSS 8.7
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
View CVE report →
CVE-2026-54065 · CVSS 8.7
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
View CVE report →
CVE-2026-46491 · CVSS 8.6
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
View CVE report →
CVE-2026-52854 · CVSS 8.6
mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function
View CVE report →
CVE-2026-55691 · CVSS 8.6
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template
View CVE report →
CVE-2026-42612 · CVSS 8.5
Grav Vulnerable to Publisher-Level Stored XSS via Unquoted Event Attributes
View CVE report →
CVE-2026-47198 · CVSS 8.5
Paymenter has URL parameter injection that bypasses paid plan limits at checkout
View CVE report →
CVE-2026-54329 · CVSS 8.5
Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
View CVE report →
CVE-2026-52769 · CVSS 8.3
YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
View CVE report →
CVE-2026-52771 · CVSS 8.3
YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)
View CVE report →
CVE-2026-41249 · CVSS 8.2
CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration
View CVE report →
CVE-2026-41669 · CVSS 8.2
Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests
View CVE report →
CVE-2026-41670 · CVSS 8.2
Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest
View CVE report →
CVE-2026-48118 · CVSS 8.2
NukeViet: Unauthenticated Reflected XSS in Comment Module
View CVE report →
CVE-2026-49260 · CVSS 8.2
php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)
View CVE report →
CVE-2026-52767 · CVSS 8.2
YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`
View CVE report →
CVE-2026-42606 · CVSS 8.1
AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass
View CVE report →
CVE-2026-42609 · CVSS 8.1
Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
View CVE report →
CVE-2026-47231 · CVSS 8.1
Admidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders
View CVE report →
CVE-2026-49286 · CVSS 8.1
PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
View CVE report →
CVE-2026-55173 · CVSS 8.1
AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink
View CVE report →
CVE-2026-45263 · CVSS 8
FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export
View CVE report →
CVE-2026-53932 · CVSS 8
laravel-backup-restore has an OS Command Injection during database restore
View CVE report →
CVE-2026-43884 · CVSS 7.7
AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()
View CVE report →
CVE-2026-54493 · CVSS 7.7
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations
View CVE report →
CVE-2023-49316 · CVSS 7.5
Phpseclib needs guardrails on large binaryfield integers
View CVE report →
CVE-2024-27355 · CVSS 7.5
phpseclib guardrails needed on OID length
View CVE report →
CVE-2026-11607 · CVSS 7.5
TYPO3 CMS has Broken Access Control in its Form Framework
View CVE report →
CVE-2026-34084 · CVSS 7.5
PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled
View CVE report →
CVE-2026-34463 · CVSS 7.5
MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form
View CVE report →
CVE-2026-40596 · CVSS 7.5
MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference
View CVE report →
CVE-2026-40597 · CVSS 7.5
MantisBT has a Content Security Policy bypass via attachments
View CVE report →
CVE-2026-40607 · CVSS 7.5
MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column
View CVE report →
CVE-2026-42071 · CVSS 7.5
MantisBT has a Private Bugnote Attachment Content Leak via REST API
View CVE report →
CVE-2026-42608 · CVSS 7.5
Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash component
View CVE report →
CVE-2026-43885 · CVSS 7.5
AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization
View CVE report →
CVE-2026-44011 · CVSS 7.5
Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached Behavior
View CVE report →
CVE-2026-44167 · CVSS 7.5
phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()
View CVE report →
CVE-2026-44655 · CVSS 7.5
MantisBT has Stored XSS on Move Attachments Admin Page
View CVE report →
CVE-2026-44657 · CVSS 7.5
MantisBT Vulnerable to Stored XSS in File Download
View CVE report →
CVE-2026-44832 · CVSS 7.5
Snipe-IT has Privilege Escalation via API Permissions Assignment
View CVE report →
CVE-2026-45063 · CVSS 7.5
Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator
View CVE report →
CVE-2026-45067 · CVSS 7.5
Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
View CVE report →
CVE-2026-45077 · CVSS 7.5
Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
View CVE report →
CVE-2026-47266 · CVSS 7.5
formie's unauthenticated front-end submission editing can overwrite existing submissions
View CVE report →
CVE-2026-47343 · CVSS 7.5
TYPO3 CMS: Destructive Actions on File Mount Folders
View CVE report →
CVE-2026-47346 · CVSS 7.5
TYPO3 CMS has Broken Access Control in its Form Framework
View CVE report →
CVE-2026-49741 · CVSS 7.5
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
View CVE report →
CVE-2026-49742 · CVSS 7.5
TYPO3 CMS has Broken Access Control in its Media Module
View CVE report →
CVE-2026-55690 · CVSS 7.5
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text
View CVE report →
CVE-2026-55794 · CVSS 7.5
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
View CVE report →
CVE-2026-62944 · CVSS 7.5
MantisBT: Stored XSS in print_all_bug_page_word.php
View CVE report →
CVE-2026-4776 · CVSS 7.1
Mautic has SQL Injection in API Contact Filtering
View CVE report →
CVE-2026-48507 · CVSS 7.1
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
View CVE report →
CVE-2026-59948 · CVSS 7
Composer: Arbitrary file write outside vendor via malicious transitive package name
View CVE report →