packagist
472,120 packages · packagist.org
Security Advisories in packagist
      
        Moderate
      
    
      
  
          about 11 hours ago
    
    OpenMage vulnerable to XSS in Admin Notifications
        
        packagist
        
        openmage/magento-lts
      
    
      
        Moderate
      
    
      
  
          about 11 hours ago
    
    MantisBT unauthorized disclosure of private project column configuration
        
        packagist
        
        mantisbt/mantisbt
      
    
      
        Moderate
      
    
      
  
          about 11 hours ago
    
    MantisBT lacks verification when changing a user's email address
        
        packagist
        
        mantisbt/mantisbt
      
    
      
        Moderate
      
    
      
  
          about 14 hours ago
    
    MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
        
        packagist
        
        mantisbt/mantisbt
      
    
      
        High
      
    
      
  
          about 14 hours ago
    
    MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling
        
        packagist
        
        mantisbt/mantisbt
      
    
      
        High
      
    
      
  
          5 days ago
    
    Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
        
        packagist
        
        statamic/cms
      
    
      
        High
      
    
      
  
          5 days ago
    
    Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass
        
        packagist
        
        drupal/simple_oauth
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Drupal CivicTheme Design System allows Cross-Site Scripting (XSS)
        
        packagist
        
        drupal/civictheme
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Drupal Plausible tracking is vulnerable to XSS
        
        packagist
        
        drupal/plausible_tracking
      
    
      
        High
      
    
      
  
          5 days ago
    
    Drupal CivicTheme Design System allows Forceful Browsing
        
        packagist
        
        drupal/civictheme
      
    
      
        Low
      
    
      
  
          5 days ago
    
    Drupal Umami Analytics allows Cross-Site Scripting (XSS)
        
        packagist
        
        drupal/umami_analytics
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables
        
        packagist
        
        drupal/reverse_proxy_header
      
    
      
        Moderate
      
    
      
  
          6 days ago
    
    Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax
        
        packagist
        
        code16/sharp
      
    
      
        Moderate
      
    
      
  
          6 days ago
    
    PrivateBin is missing HTML sanitization of attached filename in file size hint
        
        packagist
        
        privatebin/privatebin
      
    
      
        Moderate
      
    
      
  
          12 days ago
    
    Moodle's error handling leads to sensitive information disclosure
        
        packagist
        
        moodle/moodle
      
    
      
        Moderate
      
    
      
  
          12 days ago
    
    Moodle course access permissions are not properly checked in course_output_fragment_course_overview
        
        packagist
        
        moodle/moodle
      
    
      
        Moderate
      
    
      
  
          12 days ago
    
    Moodle sends quiz-related messages to inactive/suspended users
        
        packagist
        
        moodle/moodle
      
    
      
        High
      
    
      
  
          13 days ago
    
    Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality
        
        packagist
        
        admidio/admidio
      
    
      
        Moderate
      
    
      
  
          14 days ago
    
    ProcessWire CMS vulnerable to resource-exhaustion Denial of Service
        
        packagist
        
        processwire/processwire
      
    
      
        Moderate
      
    
      
  
          14 days ago
    
    Shopware Customer Orders can be canceled, even if refunds are disabled
        
        packagist
        
        shopware/core, shopware/platform
      
    
      
        Moderate
      
    
      
  
          14 days ago
    
    Shopware exposes sensitive user information via CSV export mapping
        
        packagist
        
        shopware/core, shopware/platform
      
    
      
        Low
      
    
      
  
          14 days ago
    
    Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
        
        packagist
        
        shopware/core, shopware/platform
      
    
      
        Low
      
    
      
  
          14 days ago
    
    Shopware vulnerable to path traversal via Plugin upload
        
        packagist
        
        shopware/core, shopware/platform
      
    
      
        Moderate
      
    
      
  
          14 days ago
    
    Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually
        
        packagist
        
        shopware/core, shopware/platform
      
    
      
        Moderate
      
    
      
  
          15 days ago
    
    Citizen vulnerable to stored XSS in sticky header button messages
        
        packagist
        
        starcitizentools/citizen-skin
      
    
      
        Moderate
      
    
      
  
          17 days ago
    
    Cargo Mediawiki Extension vulnerable to Cross-site Scripting
        
        packagist
        
        mediawiki/cargo
      
    
      
        Moderate
      
    
      
  
          18 days ago
    
    ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
        
        packagist
        
        ibexa/fieldtype-richtext
      
    
      
        Moderate
      
    
      
  
          18 days ago
    
    ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
        
        packagist
        
        ibexa/admin-ui
      
    
      
        Moderate
      
    
      
  
          18 days ago
    
    ezsystems/ezplatform-admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
        
        packagist
        
        ezsystems/ezplatform-admin-ui
      
    
      
        Moderate
      
    
      
  
          18 days ago
    
    bagisto has Cross Site Scripting (XSS) in Create New Customer
        
        packagist
        
        bagisto/bagisto
      
    
      
        Critical
      
    
      
  
          18 days ago
    
    bagisto has CSV Formula Injection in Create New Product
        
        packagist
        
        bagisto/bagisto
      
    
      
        Moderate
      
    
      
  
          18 days ago
    
    bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
        
        packagist
        
        bagisto/bagisto
      
    
      
        Moderate
      
    
      
  
          18 days ago
    
    bagisto has Server Side Template Injection (SSTI) in Product Description
        
        packagist
        
        bagisto/bagisto
      
    
      
        Low
      
    
      
  
          18 days ago
    
    LibreNMS alert-rules has a Cross-Site Scripting Vulnerability
        
        packagist
        
        librenms/librenms
      
    
      
        Low
      
    
      
  
          18 days ago
    
    PrestaShop Checkout Target PayPal merchant account hijacking from backoffice
        
        packagist
        
        prestashop/ps_checkout
      
    
      
        Moderate
      
    
      
  
          18 days ago
    
    PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure
        
        packagist
        
        prestashop/ps_checkout
      
    
      
        Critical
      
    
      
  
          18 days ago
    
    PrestaShop Checkout allows customer account takeover via email
        
        packagist
        
        prestashop/ps_checkout
      
    
      
        Moderate
      
    
      
  
          19 days ago
    
    bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)
        
        packagist
        
        bagisto/bagisto
      
    
      
        Moderate
      
    
      
  
          19 days ago
    
    LibreNMS has a Stored XSS vulnerability in its Alert Transport name field
        
        packagist
        
        librenms/librenms
      
    
      
        Moderate
      
    
      
  
          20 days ago
    
    Magento allows incorrect authorization
        
        packagist
        
        magento/project-community-edition, magento/community-edition
      
    
      
        Moderate
      
    
      
  
          20 days ago
    
    Magento vulnerable to privilege escalation due to incorrect authorization
        
        packagist
        
        magento/community-edition, magento/project-community-edition
      
    
      
        Moderate
      
    
      
  
          20 days ago
    
    Magento vulnerable to stored Cross-Site Scripting (XSS)
        
        packagist
        
        magento/community-edition, magento/project-community-edition
      
    
      
        High
      
    
      
  
          20 days ago
    
    Magento vulnerable to stored Cross-Site Scripting (XSS)
        
        packagist
        
        magento/community-edition, magento/project-community-edition
      
    
      
        High
      
    
      
  
          20 days ago
    
    Magento provides incorrect authorization through a security feature bypass
        
        packagist
        
        magento/project-community-edition, magento/community-edition
      
    
      
        Moderate
      
    
      
  
          21 days ago
    
    LibreNMS is vulnerable to Reflected-XSS in `report_this` function
        
        packagist
        
        librenms/librenms
      
    
      
        High
      
    
      
  
          24 days ago
    
    Bagisto is vulnerable to XSS through Admin Panel's product creation path
        
        packagist
        
        bagisto/bagisto
      
    
      
        Moderate
      
    
      
  
          25 days ago
    
    Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw
        
        packagist
        
        alt-design/alt-redirect
      
    
      
        Low
      
    
      
  
          25 days ago
    
    drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
        
        packagist
        
        drupal-pattern-lab/unified-twig-extensions
      
    
      
        Moderate
      
    
      
  
          27 days ago
    
    VaahCMS is vulnerable to XSS through its Avatar Upload endpoint
        
        packagist
        
        webreinvent/vaahcms
      
    
      
        Critical
      
    
      
  
          27 days ago
    
    Melis Platform CMS Unauthenticated File Upload Leading to RCE
        
        packagist
        
        melisplatform/melis-cms-slider
      
    
      
        Critical
      
    
      
  
          27 days ago
    
    Melis Platform CMS Unauthenticated Admin Account Creation
        
        packagist
        
        melisplatform/melis-core
      
    
      
        Low
      
    
      
  
          29 days ago
    
    NovoSGA: Manipulation of User Creation Page can lead to weak password requirements
        
        packagist
        
        novosga/novosga
      
    
      
        High
      
    
      
  
          about 1 month ago
    
    phpMyFAQ duplicate email registration allows multiple accounts with the same email
        
        packagist
        
        thorsten/phpmyfaq
      
    
      
        High
      
    
      
  
          about 1 month ago
    
    Dolibarr vulnerable to RCE via the computed field parameter
        
        packagist
        
        dolibarr/dolibarr
      
    
      
        Low
      
    
      
  
          about 1 month ago
    
    Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import
        
        packagist
        
        auth0/symfony
      
    
      
        Low
      
    
      
  
          about 1 month ago
    
    Auth0 Wordpress plugin Does Not Properly Handle File Types in Bulk User Import
        
        packagist
        
        auth0/wordpress
      
    
      
        Low
      
    
      
  
          about 1 month ago
    
    laravel-auth0 SDK Does Not Properly Handle File Types in Bulk User Import
        
        packagist
        
        auth0/login
      
    
      
        Low
      
    
      
  
          about 1 month ago
    
    auth0-PHP SDK Does Not Properly Handle File Types in Bulk User Import
        
        packagist
        
        auth0/auth0-php
      
    
      
        Moderate
      
    
      
  
          about 1 month ago
    
    Joomla! CMS vulnerable to XSS via the input filter
        
        packagist
        
        joomla/filter
      
    
      
        High
      
    
      
  
          about 1 month ago
    
    Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
        
        packagist
        
        starcitizenwiki/embedvideo
      
    
      
        Low
      
    
      
  
          about 1 month ago
    
    GP247 and S-Cart have a stored cross-site scripting (XSS) vulnerability
        
        packagist
        
        gp247/core, s-cart/core
      
    
      
        Low
      
    
      
  
          about 2 months ago
    
    TYPO3 "Form to Database" extension susceptible to Cross-site Scripting
        
        packagist
        
        lavitto/typo3-form-to-database
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    Open Web Analytics Server is vulnerable to SQL Injection
        
        packagist
        
        open-web-analytics/open-web-analytics
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    Subrion CMS: Authenticated administrators are able to gain escalated access through Run SQL Query tool
        
        packagist
        
        intelliants/subrion
      
    
      
        High
      
    
      
  
          about 2 months ago
    
    Shopware: Reflective Cross Site-Scripting (XSS) in CMS components
        
        packagist
        
        shopware/core, shopware/shopware
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    TinyEnv: Inline comments not stripped properly in .env values
        
        packagist
        
        datahihi1/tiny-env
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    TinyEnv: Missing .env file not required — may cause unexpected behavior
        
        packagist
        
        datahihi1/tiny-env
      
    
      
        High
      
    
      
  
          about 2 months ago
    
    Maho is Vulnerable to Authenticated Remote Code Execution via File Upload
        
        packagist
        
        mahocommerce/maho
      
    
      
        Critical
      
    
      
  
          about 2 months ago
    
    Magento Community Edition Improper Input Validation vulnerability
        
        packagist
        
        magento/project-community-edition, magento/community-edition
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    TYPO3 CMS exposes sensitive information in an error message
        
        packagist
        
        typo3/cms-core
      
    
      
        High
      
    
      
  
          about 2 months ago
    
    TYPO3 Workspaces Module Information Disclosure
        
        packagist
        
        typo3/cms-workspaces
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    TYPO3 backend modules have Broken Access Control
        
        packagist
        
        typo3/cms-backend, typo3/cms-beuser, typo3/cms-dashboard, typo3/cms-recycler, typo3/cms-workspaces
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    TYPO3 CSV download feature information disclosure
        
        packagist
        
        typo3/cms-recordlist, typo3/cms-backend
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    TYPO3 Bookmark Toolbar vulnerable to denial of service
        
        packagist
        
        typo3/cms-backend
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    TYPO3 CMS uses insufficient entropy when generating passwords
        
        packagist
        
        typo3/cms-core
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Mautic Vulnerable to User Enumeration via Response Timing
        
        packagist
        
        mautic/core
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
        
        packagist
        
        mautic/core
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Mautic vulnerable to secret data extraction via elfinder
        
        packagist
        
        mautic/core
      
    
      
        High
      
    
      
  
          2 months ago
    
    PocketMine-MP `ResourcePackDataInfoPacket` amplification vulnerability due to lack of resource pack sequence status checking
        
        packagist
        
        pocketmine/pocketmine-mp
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Contao does not properly manage privileges for page and article fields
        
        packagist
        
        contao/contao, contao/core-bundle
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Contao can disclose sensitive information in the news module
        
        packagist
        
        contao/contao, contao/core-bundle
      
    Filter by Severity
Filter by Package
          
            moodle/moodle
            425
          
            magento/community-edition
            325
          
            typo3/cms
            166
          
            pimcore/pimcore
            120
          
            dolibarr/dolibarr
            117
          
            phpmyadmin/phpmyadmin
            107
          
            typo3/cms-core
            107
          
            microweber/microweber
            103
          
            drupal/core
            99
          
            silverstripe/framework
            90
          
            librenms/librenms
            86
          
            magento/project-community-edition
            84
          
            thorsten/phpmyfaq
            74
          
            drupal/drupal
            71
          
            concrete5/concrete5
            67
          
            shopware/platform
            62
          
            symfony/symfony
            58
          
            craftcms/cms
            53
          
            shopware/core
            51
          
            baserproject/basercms
            47
          
            mautic/core
            47
          
            mantisbt/mantisbt
            45
          
            nilsteampassnet/teampass
            42
          
            showdoc/showdoc
            41
          
            froxlor/froxlor
            40
          
            intelliants/subrion
            40
          
            snipe/snipe-it
            38
          
            zendframework/zendframework1
            32
          
            shopware/shopware
            31
          
            getgrav/grav
            30
          
            contao/core-bundle
            29
          
            mediawiki/core
            28
          
            prestashop/prestashop
            27
          
            centreon/centreon
            27
          
            pocketmine/pocketmine-mp
            25
          
            magento/core
            24
          
            getkirby/cms
            24
          
            simplesamlphp/simplesamlphp
            23
          
            grumpydictator/firefly-iii
            23
          
            laravel/framework
            23
          
            remdex/livehelperchat
            23
          
            tribalsystems/zenario
            22
          
            phpoffice/phpspreadsheet
            22
          
            zendframework/zendframework
            22
          
            cockpit-hq/cockpit
            20
          
            funadmin/funadmin
            20
          
            typo3/cms-backend
            20
          
            contao/contao
            19
          
            topthink/framework
            19
          
            openmage/magento-lts
            18
          
            genix/cms
            18
          
            forkcms/forkcms
            18
          
            ezsystems/ezpublish-kernel
            17
          
            yetiforce/yetiforce-crm
            17
          
            cakephp/cakephp
            17
          
            francoisjacquet/rosariosis
            17
          
            opencart/opencart
            17
          
            phpbb/phpbb
            16
          
            bolt/bolt
            15
          
            silverstripe/cms
            15
          
            ec-cube/ec-cube
            15
          
            pimcore/admin-ui-classic-bundle
            15
          
            october/system
            15
          
            smarty/smarty
            15
          
            admidio/admidio
            14
          
            phpmailer/phpmailer
            14
          
            codeigniter4/framework
            14
          
            modx/revolution
            14
          
            feehi/cms
            14
          
            yeswiki/yeswiki
            14
          
            dompdf/dompdf
            14
          
            studio-42/elfinder
            13
          
            impresscms/impresscms
            13
          
            elefant/cms
            13
          
            lavalite/cms
            13
          
            symfony/security
            13
          
            phpmyfaq/phpmyfaq
            13
          
            alextselegidis/easyappointments
            13
          
            bagisto/bagisto
            12
          
            wwbn/avideo
            12
          
            sylius/sylius
            12
          
            wallabag/wallabag
            12
          
            tinymce/tinymce
            11
          
            ezsystems/ezplatform-kernel
            11
          
            nukeviet/nukeviet
            11
          
            october/october
            11
          
            feehi/feehicms
            11
          
            TinyMCE
            11
          
            sulu/sulu
            11
          
            tinymce
            11
          
            yiisoft/yii2
            11
          
            pagekit/pagekit
            11
          
            symfony/security-http
            11
          
            leantime/leantime
            11
          
            ezsystems/ezplatform-admin-ui
            10
          
            ssddanbrown/bookstack
            10
          
            ezsystems/ezpublish-legacy
            10
          
            statamic/cms
            10
          
            symfony/http-foundation
            10
          
            spatie/browsershot
            10
          
            croogo/croogo
            9
          
            twig/twig
            9
          
            pimcore/customer-management-framework-bundle
            9
          
            contao/core
            9
          
            pterodactyl/panel
            9
          
            starcitizentools/citizen-skin
            9
          
            concrete5/core
            9
          
            in2code/femanager
            9
          
            billz/raspap-webgui
            9
          
            kevinpapst/kimai2
            9
          
            in2code/powermail
            9
          
            october/cms
            8
          
            codiad/codiad
            8
          
            silverstripe/graphql
            8
          
            directmailteam/direct-mail
            8
          
            silverstripe/admin
            8
          
            gilacms/gila
            8
          
            composer/composer
            8
          
            facturascripts/facturascripts
            8
          
            tecnickcom/tcpdf
            8
          
            joomla/joomla-cms
            8
          
            flarum/core
            8
          
            october/backend
            7
          
            passbolt/passbolt_api
            7
          
            wpglobus/wpglobus
            7
          
            yiisoft/yii2-dev
            7
          
            simplesamlphp/saml2
            7
          
            redaxo/source
            7
          
            vrana/adminer
            7
          
            symfony/http-kernel
            7
          
            unopim/unopim
            7
          
            backdrop/backdrop
            7
          
            shopxo/shopxo
            7
          
            ibexa/admin-ui
            6
          
            yourls/yourls
            6
          
            drupal/core-recommended
            6
          
            guzzlehttp/guzzle
            6
          
            api-platform/core
            6
          
            icecoder/icecoder
            6
          
            typo3/cms-install
            6
          
            zoujingli/thinkadmin
            6
          
            oro/platform
            6
          
            gleez/cms
            6
          
            nystudio107/craft-seomatic
            6
          
            phpseclib/phpseclib
            6
          
            adodb/adodb-php
            6
          
            dweeves/magmi
            6
          
            pear/archive_tar
            6
          
            anchorcms/anchor-cms
            5
          
            bottelet/flarepoint
            5
          
            mautic/core-lib
            5
          
            thinkcmf/thinkcmf
            5
          
            phpservermon/phpservermon
            5
          
            cachethq/cachet
            5
          
            processwire/processwire
            5
          
            illuminate/database
            5
          
            woocommerce/woocommerce
            5
          
            ibexa/core
            5
          
            phpxmlrpc/phpxmlrpc
            5
          
            gugoan/economizzer
            5
          
            getformwork/formwork
            5
          
            elgg/elgg
            5
          
            neos/flow
            5
          
            typo3/flow
            5
          
            limesurvey/limesurvey
            5
          
            tcg/voyager
            5
          
            kimai/kimai
            5
          
            juzaweb/cms
            5
          
            symfony/security-core
            5
          
            neos/neos
            5
          
            reportico-web/reportico
            4
          
            tastyigniter/tastyigniter
            4
          
            enshrined/svg-sanitize
            4
          
            typo3/html-sanitizer
            4
          
            auth0/wordpress
            4
          
            typo3/cms-frontend
            4
          
            pixelfed/pixelfed
            4
          
            yiisoft/yii
            4
          
            codeigniter4/shield
            4
          
            ezsystems/ezplatform
            4
          
            friendsofsymfony/user-bundle
            4
          
            pyrocms/pyrocms
            4
          
            oro/commerce
            4
          
            ibexa/fieldtype-richtext
            4
          
            wintercms/winter
            4
          
            shopware/storefront
            4
          
            sylius/resource-bundle
            4
          
            sjbr/sr-feuser-register
            4
          
            evolutioncms/evolution
            4
          
            wp-premium/gravityforms
            4
          
            flarum/framework
            4
          
            ezyang/htmlpurifier
            4
          
            zendframework/zendopenid
            4
          
            livewire/livewire
            4
          
            automad/automad
            4
          
            elmsln/haxcms
            4
          
            bytefury/crater
            4
          
            notrinos/notrinos-erp
            4
          
            dcat/laravel-admin
            4
          
            moonshine/moonshine
            4
      
      Filter by Repository
          
            https://github.com/moodle/moodle
            250
          
          
            https://github.com/pimcore/pimcore
            116
          
          
            https://github.com/TYPO3/typo3
            94
          
          
            https://github.com/microweber/microweber
            90
          
          
            https://github.com/librenms/librenms
            77
          
          
            https://github.com/thorsten/phpmyfaq
            69
          
          
            https://github.com/silverstripe/silverstripe-framework
            68
          
          
            https://github.com/symfony/symfony
            64
          
          
            https://github.com/Dolibarr/dolibarr
            60
          
          
            https://github.com/mautic/mautic
            46
          
          
            https://github.com/phpmyadmin/phpmyadmin
            45
          
          
            https://github.com/concretecms/concretecms
            44
          
          
            https://github.com/shopware/platform
            43
          
          
            https://github.com/mantisbt/mantisbt
            42
          
          
            https://github.com/craftcms/cms
            41
          
          
            https://github.com/shopware/shopware
            40
          
          
            https://github.com/star7th/showdoc
            39
          
          
            https://github.com/magento/magento2
            38
          
          
            https://github.com/octobercms/october
            36
          
          
            https://github.com/contao/contao
            30
          
          
            https://github.com/snipe/snipe-it
            30
          
          
            https://github.com/baserproject/basercms
            26
          
          
            https://github.com/froxlor/froxlor
            26
          
          
            https://github.com/pmmp/PocketMine-MP
            25
          
          
            https://github.com/getgrav/grav
            24
          
          
            https://github.com/PrestaShop/PrestaShop
            23
          
          
            https://github.com/firefly-iii/firefly-iii
            23
          
          
            https://github.com/TYPO3/TYPO3.CMS
            23
          
          
            https://github.com/nilsteampassnet/TeamPass
            23
          
          
            https://github.com/livehelperchat/livehelperchat
            23
          
          
            https://github.com/PHPOffice/PhpSpreadsheet
            22
          
          
            https://github.com/getkirby/kirby
            22
          
          
            https://github.com/laravel/framework
            21
          
          
            https://github.com/funadmin/funadmin
            20
          
          
            https://github.com/simplesamlphp/simplesamlphp
            20
          
          
            https://github.com/nilsteampassnet/teampass
            19
          
          
            https://github.com/intelliants/subrion
            19
          
          
            https://github.com/TYPO3-CMS/core
            19
          
          
            https://github.com/OpenMage/magento-lts
            18
          
          
            https://github.com/liufee/cms
            17
          
          
            https://github.com/yetiforcecompany/yetiforcecrm
            16
          
          
            https://github.com/forkcms/forkcms
            16
          
          
            https://github.com/dompdf/dompdf
            15
          
          
            https://github.com/centreon/centreon
            15
          
          
            https://github.com/PHPMailer/PHPMailer
            15
          
          
            https://github.com/thorsten/phpMyFAQ
            15
          
          
            https://github.com/zendframework/zendframework
            15
          
          
            https://github.com/drupal/core
            15
          
          
            https://github.com/cockpit-hq/cockpit
            14
          
          
            https://github.com/pimcore/admin-ui-classic-bundle
            14
          
          
            https://github.com/modxcms/revolution
            12
          
          
            https://github.com/smarty-php/smarty
            12
          
          
            https://github.com/yiisoft/yii2
            12
          
          
            https://github.com/centreon/centreon-archived
            12
          
          
            https://sourceforge.net/projects/phpmyadmin.sourceforge.net
            12
          
          
            https://github.com/YesWiki/yeswiki
            12
          
          
            https://github.com/codeigniter4/CodeIgniter4
            12
          
          
            https://github.com/top-think/framework
            11
          
          
            https://github.com/Sylius/Sylius
            11
          
          
            https://github.com/tinymce/tinymce
            11
          
          
            https://github.com/Leantime/leantime
            11
          
          
            https://github.com/dolibarr/dolibarr
            11
          
          
            https://github.com/Studio-42/elFinder
            11
          
          
            https://github.com/ezsystems/ezpublish-kernel
            11
          
          
            https://github.com/sulu/sulu
            11
          
          
            https://github.com/WWBN/AVideo
            11
          
          
            https://github.com/cakephp/cakephp
            11
          
          
            https://github.com/wallabag/wallabag
            10
          
          
            https://github.com/bolt/bolt
            10
          
          
            https://github.com/opencart/opencart
            10
          
          
            https://github.com/semplon/GeniXCMS
            10
          
          
            https://github.com/spatie/browsershot
            9
          
          
            https://github.com/bagisto/bagisto
            9
          
          
            https://github.com/alextselegidis/easyappointments
            9
          
          
            https://github.com/LavaLite/cms
            9
          
          
            https://github.com/pterodactyl/panel
            9
          
          
            https://github.com/StarCitizenTools/mediawiki-skins-Citizen
            9
          
          
            https://github.com/statamic/cms
            9
          
          
            https://github.com/kevinpapst/kimai2
            9
          
          
            https://github.com/neorazorx/facturascripts
            9
          
          
            https://github.com/GilaCMS/gila
            8
          
          
            https://github.com/admidio/admidio
            8
          
          
            https://github.com/tecnickcom/TCPDF
            8
          
          
            https://github.com/Froxlor/Froxlor
            8
          
          
            https://github.com/TribalSystems/Zenario
            8
          
          
            https://github.com/twigphp/Twig
            8
          
          
            https://github.com/pimcore/customer-data-framework
            8
          
          
            https://github.com/francoisjacquet/rosariosis
            8
          
          
            https://github.com/croogo/croogo
            8
          
          
            https://github.com/RaspAP/raspap-webgui
            8
          
          
            https://github.com/flarum/framework
            8
          
          
            https://github.com/ezsystems/ezplatform-admin-ui
            8
          
          
            https://github.com/composer/composer
            7
          
          
            https://github.com/wintercms/winter
            7
          
          
            https://github.com/d4wner/Vulnerabilities-Report
            7
          
          
            https://github.com/ezsystems/ezplatform-kernel
            7
          
          
            https://github.com/unopim/unopim
            7
          
          
            https://github.com/passbolt/passbolt_api
            7
          
          
            https://github.com/Codiad/Codiad
            7
          
          
            https://github.com/pagekit/pagekit
            7
          
          
            https://github.com/phpseclib/phpseclib
            6
          
          
            https://github.com/guzzle/guzzle
            6
          
          
            https://github.com/gleez/cms
            6
          
          
            https://github.com/silverstripe/silverstripe-graphql
            6
          
          
            https://github.com/auth0/auth0-PHP
            6
          
          
            https://github.com/ADOdb/ADOdb
            6
          
          
            https://gitlab.com/francoisjacquet/rosariosis
            6
          
          
            https://github.com/api-platform/core
            6
          
          
            https://github.com/ImpressCMS/impresscms
            6
          
          
            https://github.com/Admidio/admidio
            6
          
          
            https://github.com/LimeSurvey/LimeSurvey
            6
          
          
            https://github.com/bookstackapp/bookstack
            6
          
          
            https://github.com/vrana/adminer
            6
          
          
            https://github.com/oroinc/orocommerce
            6
          
          
            https://github.com/ezsystems/ezpublish-legacy
            6
          
          
            https://github.com/nystudio107/craft-seomatic
            6
          
          
            https://github.com/dub-flow/vulnerability-research
            5
          
          
            https://github.com/gggeek/phpxmlrpc
            5
          
          
            https://github.com/Bottelet/DaybydayCRM
            5
          
          
            https://github.com/contao/core
            5
          
          
            https://github.com/in2code-de/femanager
            5
          
          
            https://github.com/nukeviet/nukeviet
            5
          
          
            https://github.com/backdrop/backdrop
            5
          
          
            https://github.com/thinkcmf/thinkcmf
            5
          
          
            https://github.com/zendframework/zf1
            5
          
          
            https://github.com/ibexa/core
            5
          
          
            https://github.com/oroinc/platform
            5
          
          
            https://github.com/ibexa/admin-ui
            5
          
          
            https://github.com/jbroadway/elefant
            5
          
          
            https://github.com/getformwork/formwork
            5
          
          
            https://github.com/shopware5/shopware
            5
          
          
            https://github.com/pear/Archive_Tar
            5
          
          
            https://github.com/reportico-web/reportico
            4
          
          
            https://github.com/BookStackApp/BookStack
            4
          
          
            https://github.com/oroinc/crm
            4
          
          
            https://github.com/phpservermon/phpservermon
            4
          
          
            https://github.com/pixelfed/pixelfed
            4
          
          
            https://github.com/Sylius/SyliusResourceBundle
            4
          
          
            https://github.com/appwrite/appwrite
            4
          
          
            https://github.com/fiveai/Cachet
            4
          
          
            https://github.com/hieuminhnv/Zenario-CMS-last-version
            4
          
          
            https://github.com/yourls/yourls
            4
          
          
            https://github.com/codeigniter4/shield
            4
          
          
            https://github.com/GiacoLenzo2109/MoonShine_Software_PoCs
            4
          
          
            https://github.com/ezsystems/ezplatform-richtext
            4
          
          
            https://github.com/TYPO3/html-sanitizer
            4
          
          
            https://github.com/Cockpit-HQ/Cockpit
            4
          
          
            https://github.com/zoujingli/ThinkAdmin
            4
          
          
            https://github.com/in2code-de/powermail
            4
          
          
            https://github.com/haxtheweb/issues
            4
          
          
            https://github.com/darylldoyle/svg-sanitizer
            4
          
          
            https://github.com/crater-invoice/crater
            4
          
          
            https://github.com/livewire/livewire
            4
          
          
            https://github.com/kimai/kimai
            4
          
          
            https://github.com/PrivateBin/PrivateBin
            4
          
          
            https://github.com/progprnv/CVE-Reports
            4
          
          
            https://github.com/froxlor/Froxlor
            4
          
          
            https://github.com/silverstripe/silverstripe-admin
            4
          
          
            https://github.com/ezsystems/ezplatform
            4
          
          
            https://github.com/brefphp/bref
            4
          
          
            https://github.com/auth0/wordpress
            3
          
          
            https://github.com/yiisoft/yii
            3
          
          
            https://github.com/liufee/feehicms
            3
          
          
            https://github.com/idno/known
            3
          
          
            https://github.com/Sylius/PayPalPlugin
            3
          
          
            https://github.com/thephpleague/commonmark
            3
          
          
            https://github.com/notrinos/notrinoserp
            3
          
          
            https://github.com/qcubed/qcubed
            3
          
          
            https://github.com/PrestaShopCorp/ps_checkout
            3
          
          
            https://github.com/artesaos/seotools
            3
          
          
            https://github.com/wikimedia/mediawiki
            3
          
          
            https://github.com/uvdesk/community-skeleton
            3
          
          
            https://github.com/TYPO3-Solr/ext-solr
            3
          
          
            https://github.com/PrestaShop/productcomments
            3
          
          
            https://github.com/ezsystems/ezplatform-http-cache
            3
          
          
            https://github.com/verbb/formie
            3
          
          
            https://github.com/verbb/comments
            3
          
          
            https://github.com/phpbb/phpbb
            3
          
          
            https://github.com/aimeos/ai-admin-graphql
            3
          
          
            https://github.com/simplesamlphp/saml2
            3
          
          
            https://github.com/flarum/core
            3
          
          
            https://github.com/UniSharp/laravel-filemanager
            3
          
          
            https://github.com/guzzle/psr7
            3
          
          
            https://github.com/woocommerce/woocommerce
            3
          
          
            https://github.com/ibexa/fieldtype-richtext
            3
          
          
            https://github.com/grokability/snipe-it
            3
          
          
            https://github.com/uasoft-indonesia/badaso
            3
          
          
            https://github.com/phpbb/phpbb-app
            3
          
          
            https://github.com/joomla/joomla-cms
            3
          
          
            https://github.com/FriendsOfSymfony/FOSUserBundle
            3
          
          
            https://github.com/quickapps/cms
            3
          
          
            https://github.com/opensource-workshop/connect-cms
            3
          
          
            https://github.com/thedevdojo/voyager
            3
          
          
            https://github.com/alexbsec/CVEs
            3
          
          
            https://github.com/belong2yourself/vulnerabilities
            3
          
          
            https://github.com/facade/ignition
            3
          
          
            https://github.com/Rudloff/alltube
            3
          
          
            https://github.com/redaxo/redaxo
            3
          
          
            https://github.com/xjzzzxx/vulFound
            3