packagist
OSS Librariespackage-ecosystem
Latest CVEs
The 15 most recently published vulnerabilities affecting packagist.
- GHSA-jr78-w6w5-m8f8Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
- GHSA-9rcc-pmj8-ffhrSemantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
- GHSA-2xmm-m4wv-3fjhOctober CMS: Incomplete Scheme Validation in Image Resizer
- CVE-2023-50462An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin....5.3
- CVE-2023-50459An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to e...5.4
- CVE-2023-50461An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitra...8.8
- CVE-2023-45023The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.4.2
- GHSA-8rr7-cvq3-gmfhleague/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
- GHSA-jjv6-8j6v-6j52league/commonmark: Denial of service in the SmartPunct and Attributes extensions
- GHSA-f8fg-pg57-v4j8league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
- GHSA-j8pm-gj4c-rq4xleague/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
- GHSA-7w8c-qgxg-m7jxLibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
- GHSA-pg62-f8g4-4wqhphpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
- GHSA-mf8r-wm2w-f8c5phpMyFAQ public FAQ APIs expose inactive FAQ content
- GHSA-88g4-74f3-63x9phpMyFAQ has Potential Authenticated Path Traversal in PDF Export