Vendor Intelligence

composer

69 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.

CVE-2026-42611 · CVSS 8.9

Grav is Vulnerable to Stored XSS via Tag Injection

View CVE report →
CVE-2026-24425 · CVSS 8.8

Twig: Possible sandbox bypass when using a source policy

View CVE report →
CVE-2026-41235 · CVSS 8.8

Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement

View CVE report →
CVE-2026-42605 · CVSS 8.8

AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload

View CVE report →
CVE-2026-42843 · CVSS 8.8

Grav API Privilege Escalation to Super Admin

View CVE report →
CVE-2026-44521 · CVSS 8.8

elFinder MySQL has a SQL Injection in its Volume Driver (elFinderVolumeMySQL)

View CVE report →
CVE-2026-44741 · CVSS 8.8

Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter

View CVE report →
CVE-2026-45578 · CVSS 8.8

AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL

View CVE report →
CVE-2026-52775 · CVSS 8.8

YesWiki has Authenticated SQL Injection via ReactionManager

View CVE report →
CVE-2026-41147 · CVSS 8.7

NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request class

View CVE report →
CVE-2026-45270 · CVSS 8.7

CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule

View CVE report →
CVE-2026-47743 · CVSS 8.7

Shopper: Multiple data integrity and disclosure issues in admin Livewire components

View CVE report →
CVE-2026-49259 · CVSS 8.7

NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

View CVE report →
CVE-2026-49283 · CVSS 8.7

SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass

View CVE report →
CVE-2026-54064 · CVSS 8.7

NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module

View CVE report →
CVE-2026-54065 · CVSS 8.7

NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

View CVE report →
CVE-2026-46491 · CVSS 8.6

SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion

View CVE report →
CVE-2026-52854 · CVSS 8.6

mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function

View CVE report →
CVE-2026-55691 · CVSS 8.6

StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template

View CVE report →
CVE-2026-42612 · CVSS 8.5

Grav Vulnerable to Publisher-Level Stored XSS via Unquoted Event Attributes

View CVE report →
CVE-2026-47198 · CVSS 8.5

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

View CVE report →
CVE-2026-54329 · CVSS 8.5

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

View CVE report →
CVE-2026-52769 · CVSS 8.3

YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`

View CVE report →
CVE-2026-52771 · CVSS 8.3

YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)

View CVE report →
CVE-2026-41249 · CVSS 8.2

CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration

View CVE report →
CVE-2026-41669 · CVSS 8.2

Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests

View CVE report →
CVE-2026-41670 · CVSS 8.2

Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest

View CVE report →
CVE-2026-48118 · CVSS 8.2

NukeViet: Unauthenticated Reflected XSS in Comment Module

View CVE report →
CVE-2026-49260 · CVSS 8.2

php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)

View CVE report →
CVE-2026-52767 · CVSS 8.2

YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`

View CVE report →
CVE-2026-42606 · CVSS 8.1

AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass

View CVE report →
CVE-2026-42609 · CVSS 8.1

Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic

View CVE report →
CVE-2026-47231 · CVSS 8.1

Admidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders

View CVE report →
CVE-2026-49286 · CVSS 8.1

PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)

View CVE report →
CVE-2026-55173 · CVSS 8.1

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

View CVE report →
CVE-2026-45263 · CVSS 8

FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export

View CVE report →
CVE-2026-53932 · CVSS 8

laravel-backup-restore has an OS Command Injection during database restore

View CVE report →
CVE-2026-43884 · CVSS 7.7

AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()

View CVE report →
CVE-2026-54493 · CVSS 7.7

Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations

View CVE report →
CVE-2023-49316 · CVSS 7.5

Phpseclib needs guardrails on large binaryfield integers

View CVE report →
CVE-2024-27355 · CVSS 7.5

phpseclib guardrails needed on OID length

View CVE report →
CVE-2026-11607 · CVSS 7.5

TYPO3 CMS has Broken Access Control in its Form Framework

View CVE report →
CVE-2026-34084 · CVSS 7.5

PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled

View CVE report →
CVE-2026-34463 · CVSS 7.5

MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form

View CVE report →
CVE-2026-40596 · CVSS 7.5

MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference

View CVE report →
CVE-2026-40597 · CVSS 7.5

MantisBT has a Content Security Policy bypass via attachments

View CVE report →
CVE-2026-40607 · CVSS 7.5

MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column

View CVE report →
CVE-2026-42071 · CVSS 7.5

MantisBT has a Private Bugnote Attachment Content Leak via REST API

View CVE report →
CVE-2026-42608 · CVSS 7.5

Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash component

View CVE report →
CVE-2026-43885 · CVSS 7.5

AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization

View CVE report →
CVE-2026-44011 · CVSS 7.5

Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached Behavior

View CVE report →
CVE-2026-44167 · CVSS 7.5

phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()

View CVE report →
CVE-2026-44655 · CVSS 7.5

MantisBT has Stored XSS on Move Attachments Admin Page

View CVE report →
CVE-2026-44657 · CVSS 7.5

MantisBT Vulnerable to Stored XSS in File Download

View CVE report →
CVE-2026-44832 · CVSS 7.5

Snipe-IT has Privilege Escalation via API Permissions Assignment

View CVE report →
CVE-2026-45063 · CVSS 7.5

Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator

View CVE report →
CVE-2026-45067 · CVSS 7.5

Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address

View CVE report →
CVE-2026-45077 · CVSS 7.5

Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener

View CVE report →
CVE-2026-47266 · CVSS 7.5

formie's unauthenticated front-end submission editing can overwrite existing submissions

View CVE report →
CVE-2026-47343 · CVSS 7.5

TYPO3 CMS: Destructive Actions on File Mount Folders

View CVE report →
CVE-2026-47346 · CVSS 7.5

TYPO3 CMS has Broken Access Control in its Form Framework

View CVE report →
CVE-2026-49741 · CVSS 7.5

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

View CVE report →
CVE-2026-49742 · CVSS 7.5

TYPO3 CMS has Broken Access Control in its Media Module

View CVE report →
CVE-2026-55690 · CVSS 7.5

StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text

View CVE report →
CVE-2026-55794 · CVSS 7.5

Craft CMS: Potential authenticated Remote Code Execution via referrer redirect

View CVE report →
CVE-2026-62944 · CVSS 7.5

MantisBT: Stored XSS in print_all_bug_page_word.php

View CVE report →
CVE-2026-4776 · CVSS 7.1

Mautic has SQL Injection in API Contact Filtering

View CVE report →
CVE-2026-48507 · CVSS 7.1

Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users

View CVE report →
CVE-2026-59948 · CVSS 7

Composer: Arbitrary file write outside vendor via malicious transitive package name

View CVE report →