Packagist Package Vulnerabilities
All 948 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,292 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 551.drupal/umami_analytics1 CVE
- 552.duncanmcclean/guest-entries1 CVE
- 553.easycorp/easyadmin-bundle1 CVE
- 554.ecodev/newsletter1 CVE
- 555.ectouch/ectouch1 CVE
- 556.ether/logs1 CVE
- 557.evoweb/sf-register1 CVE
- 558.ezsystems/ezplatform-admin-ui1 CVE
- 559.ezsystems/ezplatform-graphql1 CVE
- 560.fastly/magento21 CVE
- 561.fenom/fenom1 CVE
- 562.filament/forms1 CVE
- 563.filp/whoops1 CVE
- 564.fineuploader/php-traditional-server1 CVE
- 565.fisharebest/webtrees1 CVE
- 566.fixpunkt/fp-masterquiz1 CVE
- 567.flarum/flarum1 CVE
- 568.flarum/mentions1 CVE
- 569.flarum/nicknames1 CVE
- 570.flarum/sticky1 CVE
- 571.floriangaerber/magnesium1 CVE
- 572.fluidtypo3/vhs1 CVE
- 573.fof/byobu1 CVE
- 574.fof/pretty-mail1 CVE
- 575.fof/upload1 CVE
- 576.foodcoopshop/foodcoopshop1 CVE
- 577.fooman/tcpdf1 CVE
- 578.frappant/frp-form-answers1 CVE
- 579.friendsofsymfony1/swiftmailer1 CVE
- 580.friendsofsymfony/user-bundle1 CVE
- 581.friendsoftypo3/mediace1 CVE
- 582.friendsoftypo3/openid1 CVE
- 583.friendsoftypo3/tt-address1 CVE
- 584.frosh/adminer-platform1 CVE
- 585.frozennode/administrator1 CVE
- 586.gaoming13/wechat-php-sdk1 CVE
- 587.getgrav/grav-plugin-api1 CVE
- 588.getgrav/grav-plugin-form1 CVE
- 589.getkirby/starterkit1 CVE
- 590.globalpayments/php-sdk1 CVE
- 591.gogentooss/samlbase1 CVE
- 592.goodoneuz/pay-uz1 CVE
- 593.gp247/core1 CVE
- 594.gree/jose1 CVE
- 595.guzzlehttp/guzzle-services1 CVE
- 596.guzzlehttp/oauth-subscriber1 CVE
- 597.haffner/jh_captcha1 CVE
- 598.handcraftedinthealps/goodby-csv1 CVE
- 599.harvesthq/chosen1 CVE
- 600.hhxsv5/laravel-s1 CVE
Which Packagist packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →