Packagist Package Vulnerabilities

All 935 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,013 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 301.derhansen/sf_event_mgt2 CVEs
  2. 302.dmk/webkitpdf2 CVEs
  3. 303.drupal/civictheme2 CVEs
  4. 304.drupal/google_tag2 CVEs
  5. 305.drupal/quick_node_block2 CVEs
  6. 306.elijaa/phpmemcacheadmin2 CVEs
  7. 307.encore/laravel-admin2 CVEs
  8. 308.erusev/parsedown2 CVEs
  9. 309.exceedone/exment2 CVEs
  10. 310.exceedone/laravel-admin2 CVEs
  11. 311.filament/actions2 CVEs
  12. 312.filament/infolists2 CVEs
  13. 313.filegator/filegator2 CVEs
  14. 314.firebase/php-jwt2 CVEs
  15. 315.friendsofsymfony1/symfony12 CVEs
  16. 316.georgringer/news2 CVEs
  17. 317.getkirby/kirby2 CVEs
  18. 318.getkirby/panel2 CVEs
  19. 319.helloxz/imgurl2 CVEs
  20. 320.ibexa/admin-ui2 CVEs
  21. 321.illuminate/auth2 CVEs
  22. 322.illuminate/database2 CVEs
  23. 323.impresspages/impresspages2 CVEs
  24. 324.ipl/web2 CVEs
  25. 325.james-heinrich/getid32 CVEs
  26. 326.james-heinrich/phpthumb2 CVEs
  27. 327.jbartels/wec-map2 CVEs
  28. 328.jleehr/canto-saas-api2 CVEs
  29. 329.johnbillion/wp-crontrol2 CVEs
  30. 330.joomla/archive2 CVEs
  31. 331.joomla/filter2 CVEs
  32. 332.joomla/joomla-platform2 CVEs
  33. 333.jsdecena/laracom2 CVEs
  34. 334.khodakhah/nodcms2 CVEs
  35. 335.kitodo/presentation2 CVEs
  36. 336.laminas/laminas-diactoros2 CVEs
  37. 337.laravel/reverb2 CVEs
  38. 338.latte/latte2 CVEs
  39. 339.magneto/core2 CVEs
  40. 340.maximebf/debugbar2 CVEs
  41. 341.melisplatform/melis-cms2 CVEs
  42. 342.miniorange/miniorange-saml2 CVEs
  43. 343.mix/mix2 CVEs
  44. 344.neuron-core/neuron-ai2 CVEs
  45. 345.noumo/easyii2 CVEs
  46. 346.novosga/novosga2 CVEs
  47. 347.opensolutions/vimbadmin2 CVEs
  48. 348.open-web-analytics/open-web-analytics2 CVEs
  49. 349.oro/customer-portal2 CVEs
  50. 350.oxid-esales/oxideshop-ce2 CVEs

Which Packagist packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →