Packagist Package Vulnerabilities
All 948 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,292 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 201.ezsystems/ezplatform-kernel4 CVEs
- 202.ezyang/htmlpurifier4 CVEs
- 203.filament/filament4 CVEs
- 204.filament/tables4 CVEs
- 205.flarum/framework4 CVEs
- 206.froala/wysiwyg-editor4 CVEs
- 207.magento/product-community-edition4 CVEs
- 208.moonshine/moonshine4 CVEs
- 209.notrinos/notrinos-erp4 CVEs
- 210.oro/platform4 CVEs
- 211.pheditor/pheditor4 CVEs
- 212.phppgadmin/phppgadmin4 CVEs
- 213.pixelfed/pixelfed4 CVEs
- 214.pontedilana/php-weasyprint4 CVEs
- 215.pyrocms/pyrocms4 CVEs
- 216.reportico-web/reportico4 CVEs
- 217.silverstripe/admin4 CVEs
- 218.simplesamlphp/saml2-legacy4 CVEs
- 219.sjbr/sr-feuser-register4 CVEs
- 220.starcitizenwiki/embedvideo4 CVEs
- 221.sylius/resource-bundle4 CVEs
- 222.tastyigniter/tastyigniter4 CVEs
- 223.thorsten/phpMyFAQ4 CVEs
- 224.typo3/cms-frontend4 CVEs
- 225.wp-premium/gravityforms4 CVEs
- 226.yiisoft/yii4 CVEs
- 227.aimeos/ai-admin-graphql3 CVEs
- 228.apache-solr-for-typo3/solr3 CVEs
- 229.artesaos/seotools3 CVEs
- 230.badaso/core3 CVEs
- 231.bbpress/bbpress3 CVEs
- 232.buddypress/buddypress3 CVEs
- 233.coreshop/core-shop3 CVEs
- 234.enhavo/enhavo-app3 CVEs
- 235.ezsystems/ezpublish-legacy3 CVEs
- 236.facade/ignition3 CVEs
- 237.fixpunkt/fp-newsletter3 CVEs
- 238.geshi/geshi3 CVEs
- 239.goalgorilla/open_social3 CVEs
- 240.google/protobuf3 CVEs
- 241.joomla/framework3 CVEs
- 242.knplabs/knp-snappy3 CVEs
- 243.livewire/livewire3 CVEs
- 244.matomo/matomo3 CVEs
- 245.mediawiki/cargo3 CVEs
- 246.nitsan/ns-backup3 CVEs
- 247.orchid/platform3 CVEs
- 248.oro/commerce3 CVEs
- 249.phpunit/phpunit3 CVEs
- 250.piwik/piwik3 CVEs
Which Packagist packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →