Known Vulnerabilities for Composer by Docker
Listed below are 1 of the newest known vulnerabilities associated with "Composer" by "Docker".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65896 json | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POS... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65568 json | Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-59948 json | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untr... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59947 json | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbo... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59946 json | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing ..... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-57848 json | Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via... | Not Provided | 2026-07-18 | 2026-07-20 |
| CVE-2026-57734 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer ... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-56382 json | Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in th... | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-46767 json | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions t... | Not Provided | 2026-06-17 | 2026-06-19 |
| CVE-2026-46765 json | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions t... | Not Provided | 2026-06-17 | 2026-06-19 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Docker | Composer | 1.8.3 | |||
| Application | Docker | Composer | 1.8.2 | |||
| Application | Docker | Composer | 1.8.0 | |||
| Application | Docker | Composer | 1.7.2 | |||
| Application | Docker | Composer | 1.7.1 | |||
| Application | Docker | Composer | 1.7.0 | |||
| Application | Docker | Composer | 1.6.5 | |||
| Application | Docker | Composer | 1.6.4 | |||
| Application | Docker | Composer | 1.6.3 | |||
| Application | Docker | Composer | 1.6.2 | |||
| Application | Docker | Composer | 1.6.1 | |||
| Application | Docker | Composer | 1.6.0 | |||
| Application | Docker | Composer | 1.5.6 | |||
| Application | Docker | Composer | 1.5.5 | |||
| Application | Docker | Composer | 1.5.2 | |||
| Application | Docker | Composer | 1.5.1 | |||
| Application | Docker | Composer | 1.5.0 | |||
| Application | Docker | Composer | 1.4.3 | |||
| Application | Docker | Composer | 1.4.2 | |||
| Application | Docker | Composer | 1.4.1 |