<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Composer (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/composer.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/composer-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Composer (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-8134 – Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8134</guid>
    <pubDate>Thu, 21 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8134</strong></p>
  <p>Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code i…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40261 – Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40261</guid>
    <pubDate>Wed, 15 Apr 2026 21:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40261</strong></p>
  <p>Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplie…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40176 – Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40176</guid>
    <pubDate>Wed, 15 Apr 2026 21:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40176</strong></p>
  <p>Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious co…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50001 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50001</guid>
    <pubDate>Thu, 19 Mar 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50001</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69390 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69390</guid>
    <pubDate>Fri, 20 Feb 2026 16:22:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69390</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Business Template Blocks for WPBakery (Visual Composer) Page Builder templates-and-addons-for-wpbakery-page-builder allows Reflected XSS.This issue affects Business Template Blocks for WPBakery (Visual Composer) Page Builder: from n/a through <= 1.3.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25326 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25326</guid>
    <pubDate>Thu, 19 Feb 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25326</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23547 – Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23547</guid>
    <pubDate>Thu, 19 Feb 2026 09:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23547</strong></p>
  <p>Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CMSMasters Content Composer: from n/a through <= 2.5.8.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1426 – The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Obje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1426</guid>
    <pubDate>Wed, 18 Feb 2026 15:18:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1426</strong></p>
  <p>The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortcode_check function within the Live Composer compatibility layer. This makes it possible for authenticated attackers, with Author-level access and above, to inject a PHP Object. No known POP chain is present i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23593 – A vulnerability in the web-based management interface of HPE Aruba Networking Fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23593</guid>
    <pubDate>Tue, 27 Jan 2026 18:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23593</strong></p>
  <p>A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23592 – Insecure file operations in HPE Aruba Networking Fabric Composerâ€™s backup func...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23592</guid>
    <pubDate>Tue, 27 Jan 2026 18:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23592</strong></p>
  <p>Insecure file operations in HPE Aruba Networking Fabric Composerâ€™s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30631 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30631</guid>
    <pubDate>Tue, 06 Jan 2026 21:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30631</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Sales Funnel Builder, AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows Reflected XSS.This issue affects Woocommerce Sales Funnel Builder: from n/a through 1.1; Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Compose…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30628 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30628</guid>
    <pubDate>Wed, 31 Dec 2025 20:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30628</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows SQL Injection.This issue affects Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer): from n/a through 1.2.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14071 – The Live Composer – Free WordPress Website Builder plugin for WordPress is vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14071</guid>
    <pubDate>Sun, 21 Dec 2025 03:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14071</strong></p>
  <p>The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerabl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-13828 – SummaryA non privileged user can install and remove arbitrary packages via compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13828</guid>
    <pubDate>Tue, 02 Dec 2025 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-13828</strong></p>
  <p>SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.  ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62031 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62031</guid>
    <pubDate>Thu, 06 Nov 2025 16:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62031</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer.This issue affects tagDiv Composer: from n/a through <= 5.4.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53564 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53564</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53564</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Builder Addon lbg_radio_player_addon_visual_composer allows Reflected XSS.This issue affects HTML5 Radio Player - WPBakery Page Builder Addon: from n/a through <= 2.5.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53562 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53562</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53562</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg_universal_video_player_addon_visual_composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53559 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53559</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53559</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53299 – Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visua...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53299</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53299</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer allows Object Injection.This issue affects ThemeMakers Visual Content Composer: from n/a through <= 1.5.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48170 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48170</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48170</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48154 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48154</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48154</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder lbg_vp_youtube_vimeo_addon_visual_composer allows Reflected XSS.This issue affects Multimedia Playlist Slider Addon for WPBakery Page Builder: from n/a through <= 2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30626 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30626</guid>
    <pubDate>Thu, 14 Aug 2025 11:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30626</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder lbg_vp_youtube_vimeo_addon_visual_composer allows Reflected XSS.This issue affects Multimedia Playlist Slider Addon for WPBakery Page Builder: from n/a through <= 2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4414 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4414</guid>
    <pubDate>Fri, 04 Jul 2025 12:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4414</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through < 2.5.7.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-42977 – SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability cause...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-42977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-42977</guid>
    <pubDate>Tue, 10 Jun 2025 01:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-42977</strong></p>
  <p>SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. This allows an attacker to read or modify arbitrary files, resulting in a high impact on confidentiality and a low impact on integrity.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-42977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-42999 – SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-42999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-42999</guid>
    <pubDate>Tue, 13 May 2025 01:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-42999</strong></p>
  <p>SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-42999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31324 – SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31324</guid>
    <pubDate>Thu, 24 Apr 2025 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31324</strong></p>
  <p>SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13645 – The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13645</guid>
    <pubDate>Fri, 04 Apr 2025 06:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13645</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. This makes it possible for unauthenticated attackers to Instantiate a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13592 – The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13592</guid>
    <pubDate>Wed, 19 Feb 2025 08:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13592</strong></p>
  <p>The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the 'team-builder-vc' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in tho…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47049 – The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47049</guid>
    <pubDate>Tue, 17 Sep 2024 14:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47049</strong></p>
  <p>The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5709 – The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5709</guid>
    <pubDate>Tue, 06 Aug 2024 06:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5709</strong></p>
  <p>The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and with post permissions granted by an Administrator, to include and execute arbitrary files on the server, allowing the execution of any PHP code…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35780 – Deserialization of Untrusted Data vulnerability in Live Composer Team Page Build...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35780</guid>
    <pubDate>Wed, 19 Jun 2024 11:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35780</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3813 – The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3813</guid>
    <pubDate>Sat, 15 Jun 2024 02:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3813</strong></p>
  <p>The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35242 – Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35242</guid>
    <pubDate>Mon, 10 Jun 2024 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35242</strong></p>
  <p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially c…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35241 – Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35241</guid>
    <pubDate>Mon, 10 Jun 2024 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35241</strong></p>
  <p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installin…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32003 – wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32003</guid>
    <pubDate>Fri, 12 Apr 2024 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32003</strong></p>
  <p>wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of its testing framework to allow a browser environment (such as headless Chrome) to act as a user in the Backend or User plugin without having to go through authentication. This route is `[[URL]]/_dusk/login/[[USER ID]]/[[MANAGER]]` - where…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2725 – Information exposure vulnerability in the CIGESv2 system. A remote attacker migh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2725</guid>
    <pubDate>Fri, 22 Mar 2024 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2725</strong></p>
  <p>Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-1624 – An OS Command Injection vulnerability affecting documentation server on 3DEXPERI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1624</guid>
    <pubDate>Fri, 01 Mar 2024 16:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-1624</strong></p>
  <p>An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Release 2024 and CATIA Composer from Release R2023 through Release R2024. A specially crafted HTTP request can lead to arbitrary command execution.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24821 – Composer is a dependency Manager for the PHP language. In affected versions seve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24821</guid>
    <pubDate>Fri, 09 Feb 2024 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24821</strong></p>
  <p>Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in the context of the executing user. As such, under certain conditions arbitrary code execution may lead to local privilege escalation, provide lateral user movement or malicious code execution when Composer is invoked wit…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52206 – Deserialization of Untrusted Data vulnerability in Live Composer Team Page Build...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52206</guid>
    <pubDate>Mon, 08 Jan 2024 20:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52206</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39166 – Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39166</guid>
    <pubDate>Mon, 13 Nov 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39166</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from n/a before 4.4.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47129 – Statmic is a core Laravel content management system Composer package. Prior to v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47129</guid>
    <pubDate>Fri, 10 Nov 2023 19:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47129</strong></p>
  <p>Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-8371 – Composer before 2016-02-10 allows cache poisoning from other projects built on t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8371</guid>
    <pubDate>Thu, 21 Sep 2023 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-8371</strong></p>
  <p>Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because of the way that dist packages are cached. The cache key is derived from the package name, the dist type, and certain other data from the package repository (which may simply be a commit hash, and thus…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45414 – If a Thunderbird user quoted from an HTML email, for example by replying to the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45414</guid>
    <pubDate>Thu, 22 Dec 2022 20:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45414</strong></p>
  <p>If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was shown in the composer window. These issu…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-3477 – The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3477</guid>
    <pubDate>Mon, 14 Nov 2022 15:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-3477</strong></p>
  <p>The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31219 – Vulnerabilities in the Drive Composer allow a low privileged attacker to create ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31219</guid>
    <pubDate>Wed, 15 Jun 2022 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31219</strong></p>
  <p>Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31218 – Vulnerabilities in the Drive Composer allow a low privileged attacker to create ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31218</guid>
    <pubDate>Wed, 15 Jun 2022 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31218</strong></p>
  <p>Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31217 – Vulnerabilities in the Drive Composer allow a low privileged attacker to create ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31217</guid>
    <pubDate>Wed, 15 Jun 2022 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31217</strong></p>
  <p>Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31216 – Vulnerabilities in the Drive Composer allow a low privileged attacker to create ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31216</guid>
    <pubDate>Wed, 15 Jun 2022 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31216</strong></p>
  <p>Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24828 – Composer is a dependency manager for the PHP programming language. Integrators u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24828</guid>
    <pubDate>Wed, 13 Apr 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24828</strong></p>
  <p>Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on packagist.org for example where the composer.json's `readme` field can be used as a vector for injecting parameters into hg/Merc…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35543 – Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35543</guid>
    <pubDate>Wed, 20 Oct 2021 11:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35543</strong></p>
  <p>Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41116 – Composer is an open source dependency manager for the PHP language. In affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41116</guid>
    <pubDate>Tue, 05 Oct 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41116</strong></p>
  <p>Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38163 – SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, withou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38163</guid>
    <pubDate>Tue, 14 Sep 2021 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38163</strong></p>
  <p>SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29472 – Composer is a dependency manager for PHP. URLs for Mercurial repositories in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29472</guid>
    <pubDate>Tue, 27 Apr 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29472</strong></p>
  <p>Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed in the HgDriver if hg/Mercurial is installed on the system. The impact to Composer users directly is limited as the composer.json file is typically under their own control and sou…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35184 – The official composer docker images before 1.8.3 contain a blank password for a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35184</guid>
    <pubDate>Thu, 17 Dec 2020 02:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35184</strong></p>
  <p>The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7198 – There is a remote escalation of privilege possible for a malicious user that has...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7198</guid>
    <pubDate>Fri, 06 Nov 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7198</strong></p>
  <p>There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15227 – Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15227</guid>
    <pubDate>Thu, 01 Oct 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15227</strong></p>
  <p>Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14611 – Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14611</guid>
    <pubDate>Wed, 15 Jul 2020 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14611</strong></p>
  <p>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modi…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-8481 – For ABB products ABB Ability™ System 800xA and related system extensions version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8481</guid>
    <pubDate>Wed, 29 Apr 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-8481</strong></p>
  <p>For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-8479 – For the Central Licensing Server component used in ABB products ABB Ability™ Sys...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8479</guid>
    <pubDate>Wed, 29 Apr 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-8479</strong></p>
  <p>For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Compos…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8471 – For the Central Licensing Server component used in ABB products ABB Ability™ Sys...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8471</guid>
    <pubDate>Wed, 29 Apr 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8471</strong></p>
  <p>For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Compos…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-275</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10602 – Potential use-after-free heap error during Validate/Present calls on display HW ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10602</guid>
    <pubDate>Tue, 21 Jan 2020 07:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10602</strong></p>
  <p>Potential use-after-free heap error during Validate/Present calls on display HW composer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, QCS605, SDA660, SDM845, SDX20, SM8150</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18638 – send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18638</guid>
    <pubDate>Fri, 11 Oct 2019 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18638</strong></p>
  <p>send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any infor…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000858 – GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000858</guid>
    <pubDate>Thu, 20 Dec 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000858</strong></p>
  <p>GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in the composer window of Thunderbird/Enigmail. This vulnerability appears to have been fixed in after commit 4a4bb874f637…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7440 – IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7440</guid>
    <pubDate>Thu, 15 Mar 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7440</strong></p>
  <p>IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9844 – SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9844</guid>
    <pubDate>Wed, 12 Jul 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9844</strong></p>
  <p>SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor states that the devserver package of Visual Composer deserializes a malicious object that may cause legitimate users accessing a service, either by crashing or…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-8913 – The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8913</guid>
    <pubDate>Tue, 23 May 2017 04:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-8913</strong></p>
  <p>The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-6381 – A 3rd party development library including with Drupal 8 development dependencies...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6381</guid>
    <pubDate>Thu, 16 Mar 2017 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-6381</strong></p>
  <p>A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development dependencies aren't normal installed. You might be vulnerable to this if you are running a version of Drupal before 8.2.2. To be sure you aren't vulnerable, you c…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-7998 – The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7998</guid>
    <pubDate>Wed, 18 Jan 2017 17:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-7998</strong></p>
  <p>The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-0132 – The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0132</guid>
    <pubDate>Wed, 18 Mar 2015 10:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-0132</strong></p>
  <p>The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested enti…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-5003 – Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-5003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-5003</guid>
    <pubDate>Sun, 25 Dec 2011 01:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-5003</strong></p>
  <p>Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-5003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-2862 – Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2862</guid>
    <pubDate>Wed, 25 Jun 2008 12:36:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-2862</strong></p>
  <p>Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-2863 – Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2863</guid>
    <pubDate>Wed, 25 Jun 2008 12:36:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-2863</strong></p>
  <p>Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-4131 – Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4131</guid>
    <pubDate>Mon, 14 Aug 2006 23:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-4131</strong></p>
  <p>Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted MMS (Multimedia Messaging Service) messages that trigger the overflows in the (1) M-Notification.ind, (2) M-Retrieve.conf (Header and Body), or (3) SMIL parsers.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4131">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
