Packagist Package Vulnerabilities
All 935 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,013 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 301.derhansen/sf_event_mgt2 CVEs
- 302.dmk/webkitpdf2 CVEs
- 303.drupal/civictheme2 CVEs
- 304.drupal/google_tag2 CVEs
- 305.drupal/quick_node_block2 CVEs
- 306.elijaa/phpmemcacheadmin2 CVEs
- 307.encore/laravel-admin2 CVEs
- 308.erusev/parsedown2 CVEs
- 309.exceedone/exment2 CVEs
- 310.exceedone/laravel-admin2 CVEs
- 311.filament/actions2 CVEs
- 312.filament/infolists2 CVEs
- 313.filegator/filegator2 CVEs
- 314.firebase/php-jwt2 CVEs
- 315.friendsofsymfony1/symfony12 CVEs
- 316.georgringer/news2 CVEs
- 317.getkirby/kirby2 CVEs
- 318.getkirby/panel2 CVEs
- 319.helloxz/imgurl2 CVEs
- 320.ibexa/admin-ui2 CVEs
- 321.illuminate/auth2 CVEs
- 322.illuminate/database2 CVEs
- 323.impresspages/impresspages2 CVEs
- 324.ipl/web2 CVEs
- 325.james-heinrich/getid32 CVEs
- 326.james-heinrich/phpthumb2 CVEs
- 327.jbartels/wec-map2 CVEs
- 328.jleehr/canto-saas-api2 CVEs
- 329.johnbillion/wp-crontrol2 CVEs
- 330.joomla/archive2 CVEs
- 331.joomla/filter2 CVEs
- 332.joomla/joomla-platform2 CVEs
- 333.jsdecena/laracom2 CVEs
- 334.khodakhah/nodcms2 CVEs
- 335.kitodo/presentation2 CVEs
- 336.laminas/laminas-diactoros2 CVEs
- 337.laravel/reverb2 CVEs
- 338.latte/latte2 CVEs
- 339.magneto/core2 CVEs
- 340.maximebf/debugbar2 CVEs
- 341.melisplatform/melis-cms2 CVEs
- 342.miniorange/miniorange-saml2 CVEs
- 343.mix/mix2 CVEs
- 344.neuron-core/neuron-ai2 CVEs
- 345.noumo/easyii2 CVEs
- 346.novosga/novosga2 CVEs
- 347.opensolutions/vimbadmin2 CVEs
- 348.open-web-analytics/open-web-analytics2 CVEs
- 349.oro/customer-portal2 CVEs
- 350.oxid-esales/oxideshop-ce2 CVEs
Which Packagist packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →