Packagist Package Vulnerabilities

All 935 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,009 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 401.winter/wn-cms-module2 CVEs
  2. 402.wp-graphql/wp-graphql2 CVEs
  3. 403.yiisoft/yii2-authclient2 CVEs
  4. 404.yiisoft/yii2-gii2 CVEs
  5. 405.yiisoft/yii2-redis2 CVEs
  6. 406.yoast-seo-for-typo3/yoast_seo2 CVEs
  7. 407.yuan1994/tpadmin2 CVEs
  8. 408.zendframework/zend-db2 CVEs
  9. 409.adaptcms/adaptcms1 CVE
  10. 410.aheinze/cockpit1 CVE
  11. 411.aimeos/ai-admin-jsonadm1 CVE
  12. 412.aimeos/ai-cms-grapesjs1 CVE
  13. 413.aimeos/aimeos-laravel1 CVE
  14. 414.aimeos/aimeos-typo31 CVE
  15. 415.aimeos/pagible1 CVE
  16. 416.airesvsg/acf-to-rest-api1 CVE
  17. 417.akaunting/akaunting1 CVE
  18. 418.almirhodzic/nova-toggle-51 CVE
  19. 419.altcha-org/altcha1 CVE
  20. 420.alt-design/alt-redirect1 CVE
  21. 421.amazing/media2click1 CVE
  22. 422.ameos/ameos_tarteaucitron1 CVE
  23. 423.amphp/artax1 CVE
  24. 424.amphp/http1 CVE
  25. 425.amphp/http-client1 CVE
  26. 426.andreapollastri/cipi1 CVE
  27. 427.andrewhaine/silverstripe-form-capture1 CVE
  28. 428.aoe/restler1 CVE
  29. 429.api-platform/hal1 CVE
  30. 430.api-platform/json-api1 CVE
  31. 431.arc/web1 CVE
  32. 432.area17/twill1 CVE
  33. 433.athlon1600/youtube-downloader1 CVE
  34. 434.aureuserp/aureuserp1 CVE
  35. 435.auth0/symfony1 CVE
  36. 436.auth0/wordpress1 CVE
  37. 437.automattic/jetpack1 CVE
  38. 438.awesome-support/awesome-support1 CVE
  39. 439.ayacoo/redirect-tab1 CVE
  40. 440.b13/seo_basics1 CVE
  41. 441.backpack/filemanager1 CVE
  42. 442.barrelstrength/sprout-base-email1 CVE
  43. 443.barrelstrength/sprout-forms1 CVE
  44. 444.barryvdh/laravel-translation-manager1 CVE
  45. 445.barzahlen/barzahlen-php1 CVE
  46. 446.bcit-ci/codeigniter1 CVE
  47. 447.bcosca/fatfree1 CVE
  48. 448.bedita/bedita1 CVE
  49. 449.bednee/cooluri1 CVE
  50. 450.bigfork/silverstripe-form-capture1 CVE

Which Packagist packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →