To report a vulnerability, see our bug bounty program.
| Private network filter could be bypassed with IPv6 addresses | 2026-06-04 |
| PPSA-202606-1 Cloud | |
| Previous Composer authentication token stayed valid after regenerating it | 2026-05-26 |
| PPSA-202605-2 Cloud Self-Hosted < 2.0.33 | |
| API request signatures did not cover query parameters | 2026-05-08 |
| PPSA-202605-1 Cloud Self-Hosted < 2.0.33 | |
| Command injection through Composer via Perforce package information | 2026-04-14 |
| PPSA-202604-1 Cloud Self-Hosted < 2.0.32 Upstream CVE-2026-40261 | |
| Team invitations could be used to join a different team | 2024-10-03 |
| PPSA-202410-1 Cloud Self-Hosted < 2.0.5 | |
| Reflected cross-site scripting in the custom package form | 2024-06-12 |
| PPSA-202406-4 Cloud Self-Hosted < 2.0.3 | |
| Reflected cross-site scripting in the integration form | 2024-06-12 |
| PPSA-202406-3 Cloud Self-Hosted < 2.0.3 | |
| Open redirect in the link to join a team | 2024-06-12 |
| PPSA-202406-2 Cloud Self-Hosted < 2.0.3 | |
| Mirrored repository and notification URLs could redirect to insecure URLs | 2024-06-12 |
| PPSA-202406-1 Cloud Self-Hosted < 2.0.3 | |
| Packages of another organization could be imported | 2024-05-29 |
| PPSA-202405-1 Cloud Self-Hosted < 2.0.3 | |
| Billing team members could add packages from mirrored repositories | 2024-04-08 |
| PPSA-202404-2 Cloud Self-Hosted < 2.0.3 | |
| Organization log accessible to all organization members | 2024-04-05 |
| PPSA-202404-1 Cloud Self-Hosted < 2.0.3 | |
| Missing CSRF protection on several actions | 2024-03-21 |
| PPSA-202403-2 Cloud Self-Hosted < 2.0.2 | |
| Owners team memberships could be managed through the API | 2024-03-12 |
| PPSA-202403-1 Cloud Self-Hosted < 2.0.2 | |
| Missing CSRF protection when disconnecting OAuth accounts | 2024-02-27 |
| PPSA-202402-1 Cloud Self-Hosted < 2.0.2 | |
| Password reset links did not expire | 2024-01-03 |
| PPSA-202401-1 Cloud Self-Hosted < 2.0.1 | |
| Multi-factor authentication not required after OAuth login | 2023-09-01 |
| PPSA-202309-1 Cloud Self-Hosted = 1.12.0 | = 1.12.0-pl1 | = 1.12.0-pl2 | |
| Argument injection through Composer when processing packages | 2022-04-13 |
| PPSA-202204-1 Cloud Self-Hosted < 1.11.3 Upstream CVE-2022-24828 | |
| Command injection through Composer when processing packages | 2021-04-27 |
| PPSA-202104-1 Cloud Self-Hosted < 1.10.6 Upstream CVE-2021-29472 | |
| Sensitive data exposed through a Replicated API | 2020-03-23 |
| PPSA-202003-1 Self-Hosted < 1.9.9 Upstream CVE-2020-10590 | |
Start Free Trial
Login to create an organization and start your free trial!