Packagist Package Vulnerabilities

All 935 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,009 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 551.evoweb/sf-register1 CVE
  2. 552.ezsystems/ezplatform-admin-ui1 CVE
  3. 553.ezsystems/ezplatform-graphql1 CVE
  4. 554.fastly/magento21 CVE
  5. 555.fenom/fenom1 CVE
  6. 556.filament/forms1 CVE
  7. 557.filp/whoops1 CVE
  8. 558.fineuploader/php-traditional-server1 CVE
  9. 559.fisharebest/webtrees1 CVE
  10. 560.fixpunkt/fp-masterquiz1 CVE
  11. 561.flarum/flarum1 CVE
  12. 562.flarum/mentions1 CVE
  13. 563.flarum/nicknames1 CVE
  14. 564.flarum/sticky1 CVE
  15. 565.floriangaerber/magnesium1 CVE
  16. 566.fluidtypo3/vhs1 CVE
  17. 567.fof/byobu1 CVE
  18. 568.fof/pretty-mail1 CVE
  19. 569.fof/upload1 CVE
  20. 570.foodcoopshop/foodcoopshop1 CVE
  21. 571.fooman/tcpdf1 CVE
  22. 572.frappant/frp-form-answers1 CVE
  23. 573.friendsofsymfony1/swiftmailer1 CVE
  24. 574.friendsofsymfony/user-bundle1 CVE
  25. 575.friendsoftypo3/mediace1 CVE
  26. 576.friendsoftypo3/openid1 CVE
  27. 577.friendsoftypo3/tt-address1 CVE
  28. 578.frosh/adminer-platform1 CVE
  29. 579.frozennode/administrator1 CVE
  30. 580.gaoming13/wechat-php-sdk1 CVE
  31. 581.getgrav/grav-plugin-api1 CVE
  32. 582.getgrav/grav-plugin-form1 CVE
  33. 583.getkirby/starterkit1 CVE
  34. 584.globalpayments/php-sdk1 CVE
  35. 585.gogentooss/samlbase1 CVE
  36. 586.goodoneuz/pay-uz1 CVE
  37. 587.gp247/core1 CVE
  38. 588.gree/jose1 CVE
  39. 589.guzzlehttp/guzzle-services1 CVE
  40. 590.guzzlehttp/oauth-subscriber1 CVE
  41. 591.haffner/jh_captcha1 CVE
  42. 592.handcraftedinthealps/goodby-csv1 CVE
  43. 593.harvesthq/chosen1 CVE
  44. 594.hhxsv5/laravel-s1 CVE
  45. 595.hillelcoren/invoice-ninja1 CVE
  46. 596.himiklab/yii2-jqgrid-widget1 CVE
  47. 597.hjue/justwriting1 CVE
  48. 598.hov/jobfair1 CVE
  49. 599.hybridauth/hybridauth1 CVE
  50. 600.hyn/multi-tenant1 CVE

Which Packagist packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →