CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.
All findings (12)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| tinymce | 6.8.6 | CVE-2024-29881 | MODERATE | 0.7% | 7.0.0 | TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements |
| squizlabs/php_codesniffer dev | 3.13.4 | CVE-2026-67434 | HIGH | 0.7% | 3.13.6 | PHP_CodeSniffer gitblame report command injection via crafted filename |
| deepmerge-ts dev | 7.1.5 | CVE-2026-40345 | HIGH | 0.5% | 8.0.0 | DeepmergeTS has stack exhaustion when merging recursive object graphs |
| web-auth/webauthn-lib | 4.5.2 | CVE-2024-39912 | MODERATE | 0.4% | 4.9.0 | The FIDO2/Webauthn Support for PHP library allows enumeration of valid usernames |
| extract-zip dev | 2.0.1 | CVE-2026-56876 | HIGH | 0.4% | — | extract-zip unvalidated symlink path traversal |
| qs dev | 6.14.2 | CVE-2026-8723 | MODERATE | 0.4% | 6.15.2 | qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnl... |
| uuid dev | 8.3.2 | CVE-2026-41907 | MODERATE | 0.4% | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| nanoid | 3.3.17 | CVE-2026-67213 | HIGH | 0.3% | 3.3.18 | nanoid: custom generators can loop indefinitely when size is zero |
| tinymce | 6.8.6 | CVE-2026-47759 | HIGH | 0.3% | 7.9.3 | TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes |
| tinymce | 6.8.6 | CVE-2026-47762 | HIGH | 0.3% | 7.9.3 | TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments |
| tinymce | 6.8.6 | CVE-2026-47761 | HIGH | 0.3% | 7.9.3 | TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection |
| tinymce | 6.8.6 | CVE-2026-47760 | HIGH | 0.2% | 7.1.0 | TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs |
SBOM summary
1130 direct dependencies scanned (1130 pinned to exact versions) from composer.lock, package-lock.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.