Packagist Package Vulnerabilities

All 935 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,009 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 201.filament/tables4 CVEs
  2. 202.flarum/framework4 CVEs
  3. 203.froala/wysiwyg-editor4 CVEs
  4. 204.getformwork/formwork4 CVEs
  5. 205.league/commonmark4 CVEs
  6. 206.magento/product-community-edition4 CVEs
  7. 207.moonshine/moonshine4 CVEs
  8. 208.notrinos/notrinos-erp4 CVEs
  9. 209.oro/platform4 CVEs
  10. 210.pheditor/pheditor4 CVEs
  11. 211.phppgadmin/phppgadmin4 CVEs
  12. 212.pixelfed/pixelfed4 CVEs
  13. 213.pontedilana/php-weasyprint4 CVEs
  14. 214.pyrocms/pyrocms4 CVEs
  15. 215.reportico-web/reportico4 CVEs
  16. 216.silverstripe/admin4 CVEs
  17. 217.simplesamlphp/saml2-legacy4 CVEs
  18. 218.sjbr/sr-feuser-register4 CVEs
  19. 219.starcitizenwiki/embedvideo4 CVEs
  20. 220.sylius/resource-bundle4 CVEs
  21. 221.tastyigniter/tastyigniter4 CVEs
  22. 222.thorsten/phpMyFAQ4 CVEs
  23. 223.typo3/cms-frontend4 CVEs
  24. 224.wp-premium/gravityforms4 CVEs
  25. 225.yiisoft/yii4 CVEs
  26. 226.aimeos/ai-admin-graphql3 CVEs
  27. 227.apache-solr-for-typo3/solr3 CVEs
  28. 228.artesaos/seotools3 CVEs
  29. 229.badaso/core3 CVEs
  30. 230.bbpress/bbpress3 CVEs
  31. 231.buddypress/buddypress3 CVEs
  32. 232.coreshop/core-shop3 CVEs
  33. 233.enhavo/enhavo-app3 CVEs
  34. 234.ezsystems/ezpublish-legacy3 CVEs
  35. 235.facade/ignition3 CVEs
  36. 236.fixpunkt/fp-newsletter3 CVEs
  37. 237.geshi/geshi3 CVEs
  38. 238.goalgorilla/open_social3 CVEs
  39. 239.google/protobuf3 CVEs
  40. 240.joomla/framework3 CVEs
  41. 241.knplabs/knp-snappy3 CVEs
  42. 242.livewire/livewire3 CVEs
  43. 243.matomo/matomo3 CVEs
  44. 244.mediawiki/cargo3 CVEs
  45. 245.nitsan/ns-backup3 CVEs
  46. 246.orchid/platform3 CVEs
  47. 247.oro/commerce3 CVEs
  48. 248.phpunit/phpunit3 CVEs
  49. 249.piwik/piwik3 CVEs
  50. 250.prestashop/productcomments3 CVEs

Which Packagist packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →