Skip to main content

Vendor/product archive

getcomposer / composer CVEs

Beta · best-effort

9 CVEs tagged to getcomposer / composer0 Critical, 7 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2026-40261

Published Apr 15, 2026

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which…

CVSS 8.8 · High
evidence mentions
8
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2026-40176

Published Apr 15, 2026

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method,…

CVSS 7.8 · High
evidence mentions
8
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2025-67746

Published Dec 30, 2025

Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-24821

Published Feb 9, 2024

Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8371

Published Sep 21, 2023

Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41116

Published Oct 5, 2021

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command in…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1