Packagist Package Vulnerabilities
All 935 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,009 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 201.filament/tables4 CVEs
- 202.flarum/framework4 CVEs
- 203.froala/wysiwyg-editor4 CVEs
- 204.getformwork/formwork4 CVEs
- 205.league/commonmark4 CVEs
- 206.magento/product-community-edition4 CVEs
- 207.moonshine/moonshine4 CVEs
- 208.notrinos/notrinos-erp4 CVEs
- 209.oro/platform4 CVEs
- 210.pheditor/pheditor4 CVEs
- 211.phppgadmin/phppgadmin4 CVEs
- 212.pixelfed/pixelfed4 CVEs
- 213.pontedilana/php-weasyprint4 CVEs
- 214.pyrocms/pyrocms4 CVEs
- 215.reportico-web/reportico4 CVEs
- 216.silverstripe/admin4 CVEs
- 217.simplesamlphp/saml2-legacy4 CVEs
- 218.sjbr/sr-feuser-register4 CVEs
- 219.starcitizenwiki/embedvideo4 CVEs
- 220.sylius/resource-bundle4 CVEs
- 221.tastyigniter/tastyigniter4 CVEs
- 222.thorsten/phpMyFAQ4 CVEs
- 223.typo3/cms-frontend4 CVEs
- 224.wp-premium/gravityforms4 CVEs
- 225.yiisoft/yii4 CVEs
- 226.aimeos/ai-admin-graphql3 CVEs
- 227.apache-solr-for-typo3/solr3 CVEs
- 228.artesaos/seotools3 CVEs
- 229.badaso/core3 CVEs
- 230.bbpress/bbpress3 CVEs
- 231.buddypress/buddypress3 CVEs
- 232.coreshop/core-shop3 CVEs
- 233.enhavo/enhavo-app3 CVEs
- 234.ezsystems/ezpublish-legacy3 CVEs
- 235.facade/ignition3 CVEs
- 236.fixpunkt/fp-newsletter3 CVEs
- 237.geshi/geshi3 CVEs
- 238.goalgorilla/open_social3 CVEs
- 239.google/protobuf3 CVEs
- 240.joomla/framework3 CVEs
- 241.knplabs/knp-snappy3 CVEs
- 242.livewire/livewire3 CVEs
- 243.matomo/matomo3 CVEs
- 244.mediawiki/cargo3 CVEs
- 245.nitsan/ns-backup3 CVEs
- 246.orchid/platform3 CVEs
- 247.oro/commerce3 CVEs
- 248.phpunit/phpunit3 CVEs
- 249.piwik/piwik3 CVEs
- 250.prestashop/productcomments3 CVEs
Which Packagist packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →