Home/Product/getcomposer composer
Product

getcomposer composer

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-40261
>= 1.0.0 and <= 2.2.26
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerabil
8.8HIGH
CVE-2026-40176
>= 1.0.0 and <= 2.2.26
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerabil
7.8HIGH
CVE-2025-67746
>= 2.0.0 and < 2.2.26
Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote so
4.3MEDIUM
CVE-2025-3510
< 5.4.1
The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up t
6.4MEDIUM
CVE-2024-24821
>= 2.0.0 and < 2.2.23
Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are i
8.8HIGH
CVE-2023-43655
< 1.10.27
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.ph
6.4MEDIUM
CVE-2015-8371
all versions
Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled
8.8HIGH
CVE-2023-1596
< 4.0
The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, le
6.1MEDIUM
CVE-2022-24828
< 1.10.26
Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileCont
8.3HIGH
CVE-2021-41116
< 1.10.23
Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install
8.2HIGH
CVE-2021-29472
< 1.10.22
Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download UR
8.8HIGH
CVE-2020-15145
< 6.0.0
In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may b
6.7MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin