Getcomposer / Composer
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-40261 | Composer has Command Injection via Malicious Perforce Reference | HIGH | 8.8 | Apr 15, 2026 |
| CVE-2026-40176 | Composer is vulnerable to Command Injection via Malicious Perforce Repository | HIGH | 7.8 | Apr 15, 2026 |
| CVE-2025-67746 | Composer vulnerable to ANSI sequence injection | LOW | 1.3 | Dec 30, 2025 |
| CVE-2024-35242 | Composer vulnerable to command injection via malicious git/hg branch names | HIGH | 8.8 | Jun 10, 2024 |
| CVE-2024-35241 | Composer vulnerable to command injection via malicious git branch name | HIGH | 8.8 | Jun 10, 2024 |
| CVE-2024-24821 | Code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in Composer | HIGH | 8.8 | Feb 8, 2024 |
| CVE-2023-43655 | Remote Code Execution via web-accessible composer.phar | HIGH | 8.8 | Sep 29, 2023 |
| CVE-2015-8371 | Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side b… | HIGH | 8.8 | Sep 21, 2023 |
| CVE-2022-24828 | Missing input validation can lead to command execution in composer | HIGH | 8.8 | Apr 13, 2022 |
| CVE-2021-41116 | Command injection in composer on Windows | CRITICAL | 9.8 | Oct 5, 2021 |
| CVE-2021-29472 | Missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial in composer | HIGH | 8.8 | Apr 27, 2021 |
Showing 1 to 11 of 11 CVEs