Packagist Package Vulnerabilities

All 935 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,009 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 301.drupal/civictheme2 CVEs
  2. 302.drupal/google_tag2 CVEs
  3. 303.drupal/quick_node_block2 CVEs
  4. 304.elijaa/phpmemcacheadmin2 CVEs
  5. 305.encore/laravel-admin2 CVEs
  6. 306.erusev/parsedown2 CVEs
  7. 307.exceedone/exment2 CVEs
  8. 308.exceedone/laravel-admin2 CVEs
  9. 309.filament/actions2 CVEs
  10. 310.filament/infolists2 CVEs
  11. 311.filegator/filegator2 CVEs
  12. 312.firebase/php-jwt2 CVEs
  13. 313.friendsofsymfony1/symfony12 CVEs
  14. 314.georgringer/news2 CVEs
  15. 315.getkirby/kirby2 CVEs
  16. 316.getkirby/panel2 CVEs
  17. 317.helloxz/imgurl2 CVEs
  18. 318.ibexa/admin-ui2 CVEs
  19. 319.illuminate/auth2 CVEs
  20. 320.illuminate/database2 CVEs
  21. 321.impresspages/impresspages2 CVEs
  22. 322.ipl/web2 CVEs
  23. 323.james-heinrich/getid32 CVEs
  24. 324.james-heinrich/phpthumb2 CVEs
  25. 325.jbartels/wec-map2 CVEs
  26. 326.jleehr/canto-saas-api2 CVEs
  27. 327.johnbillion/wp-crontrol2 CVEs
  28. 328.joomla/archive2 CVEs
  29. 329.joomla/filter2 CVEs
  30. 330.joomla/joomla-platform2 CVEs
  31. 331.jsdecena/laracom2 CVEs
  32. 332.khodakhah/nodcms2 CVEs
  33. 333.kitodo/presentation2 CVEs
  34. 334.laminas/laminas-diactoros2 CVEs
  35. 335.laravel/reverb2 CVEs
  36. 336.latte/latte2 CVEs
  37. 337.magneto/core2 CVEs
  38. 338.maximebf/debugbar2 CVEs
  39. 339.melisplatform/melis-cms2 CVEs
  40. 340.miniorange/miniorange-saml2 CVEs
  41. 341.mix/mix2 CVEs
  42. 342.neuron-core/neuron-ai2 CVEs
  43. 343.noumo/easyii2 CVEs
  44. 344.novosga/novosga2 CVEs
  45. 345.opensolutions/vimbadmin2 CVEs
  46. 346.open-web-analytics/open-web-analytics2 CVEs
  47. 347.oro/customer-portal2 CVEs
  48. 348.oxid-esales/oxideshop-ce2 CVEs
  49. 349.packbackbooks/lti-1-3-php-library2 CVEs
  50. 350.passbolt/passbolt_api2 CVEs

Which Packagist packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →