Skip to content
Noroxi

getcomposer records

12 published records for vendor getcomposer.

All records

12 records
  • Command injection in composer on Windows

    CriticalCVSS 9.8No exploitEPSS 3%

    getcomposer · composerOct 5, 2021

  • Missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial in composer

    HighCVSS 8.8No exploitEPSS 5%

    getcomposer · composerApr 27, 2021

  • Composer vulnerable to command injection via malicious git/hg branch names

    HighCVSS 8.8Proof of conceptEPSS 3%

    composer · composerJun 10, 2024

  • Composer has Command Injection via Malicious Perforce Reference

    HighCVSS 8.8Proof of conceptEPSS 2%

    getcomposer · composerApr 15, 2026

  • Missing input validation can lead to command execution in composer

    HighCVSS 8.8No exploitEPSS 2%

    getcomposer · composerApr 13, 2022

  • Remote Code Execution via web-accessible composer.phar

    HighCVSS 8.8No exploitEPSS 1%

    getcomposer · composerSep 29, 2023

  • Composer vulnerable to command injection via malicious git branch name

    HighCVSS 8.8No exploitEPSS 1%

    composer · composerJun 10, 2024

  • CVE-2015-8371
    35Monitor

    Composer before 2016-02-10 allows cache poisoning from other projects built on the same host.

    HighCVSS 8.8No exploitEPSS 1%

    getcomposer · composerSep 21, 2023

  • Local privilege elevation in Composer-Setup for Windows

    HighCVSS 8.2No exploitEPSS 0%

    getcomposer · composer-setupAug 14, 2020

  • Composer is vulnerable to Command Injection via Malicious Perforce Repository

    HighCVSS 7.8Proof of conceptEPSS 1%

    getcomposer · composerApr 15, 2026

  • Code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in Composer

    HighCVSS 7.8No exploitEPSS 0%

    getcomposer · composerFeb 8, 2024

  • Composer vulnerable to ANSI sequence injection

    LowCVSS 1.3No exploitEPSS 0%

    getcomposer · composerDec 30, 2025