composer Vulnerabilities
CVE security advisories and vulnerability history for composer.
Overview
composer has 5,054 published CVE records since 2005, of which 23 are in CISA's Known Exploited Vulnerabilities catalog and 1,402 have a known public exploit. The average CVSS base score across scored CVEs is 6.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting composer products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.