Packagist Package Vulnerabilities

All 935 PHP / Composer packages with known CVEs, ranked by live CVE volume — 6,014 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 351.packbackbooks/lti-1-3-php-library2 CVEs
  2. 352.passbolt/passbolt_api2 CVEs
  3. 353.phenx/php-svg-lib2 CVEs
  4. 354.phpfastcache/phpfastcache2 CVEs
  5. 355.phpsysinfo/phpsysinfo2 CVEs
  6. 356.prestashop/blockreassurance2 CVEs
  7. 357.ptrofimov/beanstalk_console2 CVEs
  8. 358.react/http2 CVEs
  9. 359.rhukster/dom-sanitizer2 CVEs
  10. 360.s9y/serendipity2 CVEs
  11. 361.sabre/dav2 CVEs
  12. 362.s-cart/core2 CVEs
  13. 363.s-cart/s-cart2 CVEs
  14. 364.setasign/fpdi2 CVEs
  15. 365.shuchkin/simplexlsx2 CVEs
  16. 366.simogeo/filemanager2 CVEs
  17. 367.simplesamlphp/simplesamlphp-module-casserver2 CVEs
  18. 368.simplesamlphp/simplesamlphp-module-infocard2 CVEs
  19. 369.simplesamlphp/xml-security2 CVEs
  20. 370.sjbr/sr-freecap2 CVEs
  21. 371.slim/slim2 CVEs
  22. 372.solspace/craft-freeform2 CVEs
  23. 373.spatie/laravel-medialibrary2 CVEs
  24. 374.spipu/html2pdf2 CVEs
  25. 375.starcitizentools/tabber-neue2 CVEs
  26. 376.swiftmailer/swiftmailer2 CVEs
  27. 377.sylius/grid-bundle2 CVEs
  28. 378.symfony/framework-bundle2 CVEs
  29. 379.symfony/http-client2 CVEs
  30. 380.symfony/polyfill2 CVEs
  31. 381.symfony/process2 CVEs
  32. 382.symfony/runtime2 CVEs
  33. 383.symfony/twig-bridge2 CVEs
  34. 384.symfony/validator2 CVEs
  35. 385.symphonycms/symphony-22 CVEs
  36. 386.t3/dce2 CVEs
  37. 387.tikiwiki/tiki-manager2 CVEs
  38. 388.tltneon/lgsl2 CVEs
  39. 389.topthink/think2 CVEs
  40. 390.topthink/thinkphp2 CVEs
  41. 391.typo3/cms-beuser2 CVEs
  42. 392.typo3/cms-dashboard2 CVEs
  43. 393.typo3/cms-indexed-search2 CVEs
  44. 394.typo3/cms-workspaces2 CVEs
  45. 395.typo3fluid/fluid2 CVEs
  46. 396.typo3/phar-stream-wrapper2 CVEs
  47. 397.verbb/image-resizer2 CVEs
  48. 398.verbb/knock-knock2 CVEs
  49. 399.vufind/vufind2 CVEs
  50. 400.web-auth/webauthn-lib2 CVEs

Which Packagist packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →