« Back to list

Getcomposer

Getcomposer Composer: vulnerabilities and CVEs

Getcomposer Composer has 9 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months3
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-40261High (8.8)1.9%—Apr 15, 2026
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter…
CVE-2026-40176High (7.8)1.00%—Apr 15, 2026
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by…
CVE-2025-67746Low (1.3)0.45%—Dec 30, 2025
Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in…
CVE-2024-24821High (7.8)0.28%—Feb 9, 2024
Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in the context of the executing user. As…
CVE-2023-43655High (8.8)1.5%—Sep 29, 2023
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability…
CVE-2015-8371High (8.8)0.72%—Sep 21, 2023
Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because of the way that dist…
CVE-2022-24828High (8.8)1.9%—Apr 13, 2022
Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or…
CVE-2021-41116Critical (9.8)2.9%—Oct 5, 2021
Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their…
CVE-2021-29472High (8.8)4.8%—Apr 27, 2021
Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter2
  2. T1203 Exploitation for Client Execution2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Getcomposer