Packagist Package Vulnerabilities

All 948 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,292 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 201.ezsystems/ezplatform-kernel4 CVEs
  2. 202.ezyang/htmlpurifier4 CVEs
  3. 203.filament/filament4 CVEs
  4. 204.filament/tables4 CVEs
  5. 205.flarum/framework4 CVEs
  6. 206.froala/wysiwyg-editor4 CVEs
  7. 207.magento/product-community-edition4 CVEs
  8. 208.moonshine/moonshine4 CVEs
  9. 209.notrinos/notrinos-erp4 CVEs
  10. 210.oro/platform4 CVEs
  11. 211.pheditor/pheditor4 CVEs
  12. 212.phppgadmin/phppgadmin4 CVEs
  13. 213.pixelfed/pixelfed4 CVEs
  14. 214.pontedilana/php-weasyprint4 CVEs
  15. 215.pyrocms/pyrocms4 CVEs
  16. 216.reportico-web/reportico4 CVEs
  17. 217.silverstripe/admin4 CVEs
  18. 218.simplesamlphp/saml2-legacy4 CVEs
  19. 219.sjbr/sr-feuser-register4 CVEs
  20. 220.starcitizenwiki/embedvideo4 CVEs
  21. 221.sylius/resource-bundle4 CVEs
  22. 222.tastyigniter/tastyigniter4 CVEs
  23. 223.thorsten/phpMyFAQ4 CVEs
  24. 224.typo3/cms-frontend4 CVEs
  25. 225.wp-premium/gravityforms4 CVEs
  26. 226.yiisoft/yii4 CVEs
  27. 227.aimeos/ai-admin-graphql3 CVEs
  28. 228.apache-solr-for-typo3/solr3 CVEs
  29. 229.artesaos/seotools3 CVEs
  30. 230.badaso/core3 CVEs
  31. 231.bbpress/bbpress3 CVEs
  32. 232.buddypress/buddypress3 CVEs
  33. 233.coreshop/core-shop3 CVEs
  34. 234.enhavo/enhavo-app3 CVEs
  35. 235.ezsystems/ezpublish-legacy3 CVEs
  36. 236.facade/ignition3 CVEs
  37. 237.fixpunkt/fp-newsletter3 CVEs
  38. 238.geshi/geshi3 CVEs
  39. 239.goalgorilla/open_social3 CVEs
  40. 240.google/protobuf3 CVEs
  41. 241.joomla/framework3 CVEs
  42. 242.knplabs/knp-snappy3 CVEs
  43. 243.livewire/livewire3 CVEs
  44. 244.matomo/matomo3 CVEs
  45. 245.mediawiki/cargo3 CVEs
  46. 246.nitsan/ns-backup3 CVEs
  47. 247.orchid/platform3 CVEs
  48. 248.oro/commerce3 CVEs
  49. 249.phpunit/phpunit3 CVEs
  50. 250.piwik/piwik3 CVEs

Which Packagist packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →