Known Vulnerabilities for Composer by Docker
Listed below are 1 of the newest known vulnerabilities associated with "Composer" by "Docker".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40261 json | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulne... | Not Provided | 2026-04-15 | 2026-04-16 |
| CVE-2026-40176 json | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulne... | Not Provided | 2026-04-15 | 2026-04-16 |
| CVE-2026-39712 json | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in tagDiv tagDiv Composer td-comp... | Not Provided | 2026-04-08 | 2026-04-29 |
| CVE-2026-39692 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer ... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-34216 json | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpo... | Not Provided | 2026-05-19 | 2026-05-20 |
| CVE-2026-24594 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addon... | Not Provided | 2026-01-23 | 2026-04-28 |
| CVE-2026-8134 json | Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate f... | Not Provided | 2026-05-21 | 2026-05-22 |
| CVE-2025-68598 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Build... | Not Provided | 2025-12-24 | 2026-04-27 |
| CVE-2025-68574 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Vis... | Not Provided | 2025-12-24 | 2026-04-27 |
| CVE-2025-55709 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual ... | Not Provided | 2025-08-14 | 2026-04-23 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Docker | Composer | 1.8.3 | |||
| Application | Docker | Composer | 1.8.2 | |||
| Application | Docker | Composer | 1.8.0 | |||
| Application | Docker | Composer | 1.7.2 | |||
| Application | Docker | Composer | 1.7.1 | |||
| Application | Docker | Composer | 1.7.0 | |||
| Application | Docker | Composer | 1.6.5 | |||
| Application | Docker | Composer | 1.6.4 | |||
| Application | Docker | Composer | 1.6.3 | |||
| Application | Docker | Composer | 1.6.2 | |||
| Application | Docker | Composer | 1.6.1 | |||
| Application | Docker | Composer | 1.6.0 | |||
| Application | Docker | Composer | 1.5.6 | |||
| Application | Docker | Composer | 1.5.5 | |||
| Application | Docker | Composer | 1.5.2 | |||
| Application | Docker | Composer | 1.5.1 | |||
| Application | Docker | Composer | 1.5.0 | |||
| Application | Docker | Composer | 1.4.3 | |||
| Application | Docker | Composer | 1.4.2 | |||
| Application | Docker | Composer | 1.4.1 |