Known vulnerabilities in php-composer2

Vendor: SUSE
Software: php-composer2
Software CPE: cpe:2.3:o:suse:php-composer2:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting php-composer2 php-composer2 is affected by 12 known vulnerabilities: 6 high, 4 medium, 2 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU136613 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-59946
CWE-22 Medium
No
No
2.6.4-150600.3.12.1 01.07.2026 SB2026070158
SB20260721146
#VU136612 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-59948
CWE-22 Medium
No
No
2.6.4-150600.3.12.1 01.07.2026 SB2026070158
SB20260721146
#VU136611 - Information Exposure Through Log Files
CVE-2026-59947
CWE-532 Low
No
No
2.6.4-150600.3.12.1 01.07.2026 SB2026070158
SB20260721146
#VU131373 - Exposure of sensitive information to an unauthorized actor
CVE-2026-45793
CWE-200 Medium
No
No
2.6.4-150600.3.12.1 13.05.2026 SB2026051396
SB20260721146
#VU125895 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-40176
CWE-78 High
No
No
2.6.4-150600.3.9.1, 2.6.4-150600.3.12.1 14.04.2026 SB2026041445
SB2026041481
SB2026041482
and 8 more
#VU125894 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-40261
CWE-78 High
No
No
2.6.4-150600.3.9.1, 2.6.4-150600.3.12.1 14.04.2026 SB2026041445
SB2026041481
SB2026041482
and 8 more
#VU125893 - Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2025-67746
CWE-150 Medium
No
No
2.2.3-150400.3.15.1, 2.6.4-150600.3.6.1, 2.6.4-150600.3.12.1 14.04.2026 SB2026041444
SB2026041449
SB2026041450
and 2 more
#VU91685 - Command injection
CVE-2024-35242
CWE-77 High
No
No
2.2.3-150400.3.12.1, 2.6.4-150600.3.3.1, 2.6.4-150600.3.12.1 11.06.2024 SB2024061107
SB2024061108
SB2024061109
and 6 more
#VU91684 - Command injection
CVE-2024-35241
CWE-77 High
No
No
2.2.3-150400.3.12.1, 2.6.4-150600.3.3.1, 2.6.4-150600.3.12.1 11.06.2024 SB2024061107
SB2024061108
SB2024061109
and 7 more
#VU86276 - Incorrect Default Permissions
CVE-2024-24821
CWE-276 Low
No
No
2.2.3-150400.3.9.1 08.02.2024 SB2024020870
SB2024021508
SB2024022241
and 3 more
#VU81296 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-43655
CWE-94 High
No
No
2.2.3-150400.3.6.1 29.09.2023 SB2023092947
SB2023092956
SB2023092957
and 13 more
#VU62312 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-24828
CWE-78 High
No
No
2.2.3-150400.3.3.1 14.04.2022 SB2022041401
SB2022042017
SB2022090517
and 7 more