Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

composer — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting composer. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Composer is a dependency manager for PHP that enables developers to manage project libraries and their dependencies. Historically, it has been associated with vulnerabilities like remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often through compromised packages or insecure configurations. Notable security characteristics include its extensive package repository and automatic dependency resolution, which can introduce risks if not properly monitored. Major incidents include supply chain attacks where malicious code was injected into popular packages, leading to widespread exploitation. The tool's widespread adoption in PHP ecosystems makes it a critical component requiring robust security practices to mitigate potential threats from its package ecosystem.

Found 1 results / 17 Clear Filters
Top products by composer: composer windows-setup
CVE ID Title CVSS Severity Published
CVE-2020-15145 Local privilege elevation in Composer-Setup for Windows — windows-setup CWE-276 6.7 Medium 2020-08-14

This page lists every published CVE security advisory associated with composer. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.