packagist
Security Advisories in packagist
High
32 minutes ago
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
packagist
phpoffice/phpspreadsheet
Moderate
about 17 hours ago
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
packagist
dompdf/dompdf
Moderate
about 17 hours ago
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
packagist
dompdf/dompdf
Moderate
about 17 hours ago
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
packagist
dompdf/dompdf
Moderate
about 18 hours ago
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
packagist
dompdf/dompdf
Low
about 18 hours ago
Dompdf: File existence oracle via font-face stylesheet declaration
packagist
dompdf/dompdf
Moderate
2 days ago
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
packagist
guzzlehttp/psr7
Moderate
3 days ago
Guzzle: URI fragments disclosed in redirect Referer headers
packagist
guzzlehttp/guzzle
Moderate
3 days ago
Guzzle: Unbounded response cookies risk denial of service
packagist
guzzlehttp/guzzle
Moderate
3 days ago
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
packagist
guzzlehttp/guzzle
Moderate
3 days ago
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
packagist
composer/composer
Moderate
3 days ago
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
packagist
composer/composer
Moderate
3 days ago
Guzzle: Proxy-Authorization headers can be sent to origin servers
packagist
guzzlehttp/guzzle
High
3 days ago
Composer: Arbitrary file write outside vendor via malicious transitive package name
packagist
composer/composer
Moderate
6 days ago
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration
packagist
verbb/formie
Critical
7 days ago
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
packagist
pheditor/pheditor
High
7 days ago
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
packagist
pheditor/pheditor
High
7 days ago
Pheditor has an authenticated terminal command whitelist bypass
packagist
pheditor/pheditor
Moderate
8 days ago
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
packagist
adawolfa/isdoc
Moderate
8 days ago
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
packagist
mantisbt/mantisbt
Moderate
8 days ago
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
packagist
mantisbt/mantisbt
Critical
8 days ago
MantisBT: Reflected XSS in admin/install.php via unescaped printf
packagist
mantisbt/mantisbt
Moderate
8 days ago
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
packagist
phanan/koel
High
8 days ago
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths
packagist
phanan/koel
Moderate
8 days ago
Koel has SSRF through Authenticated Subsonic podcast feed URLs
packagist
phanan/koel
High
8 days ago
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations
packagist
phanan/koel
Moderate
8 days ago
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation
packagist
phanan/koel
High
8 days ago
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
packagist
mantisbt/mantisbt
Critical
8 days ago
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
packagist
mantisbt/mantisbt
High
8 days ago
MantisBT: SQL Injection via history_order Configuration Value
packagist
mantisbt/mantisbt
Critical
9 days ago
FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE
packagist
facturascripts/facturascripts
High
9 days ago
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
packagist
easycorp/easyadmin-bundle
Moderate
9 days ago
Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter
packagist
auth0/symfony
Low
9 days ago
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
packagist
facturascripts/facturascripts
High
9 days ago
FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export
packagist
facturascripts/facturascripts
High
9 days ago
FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents
packagist
facturascripts/facturascripts
Critical
9 days ago
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`
packagist
facturascripts/facturascripts
Moderate
10 days ago
Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access
packagist
kimai/kimai
High
10 days ago
Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP
packagist
kimai/kimai
Moderate
10 days ago
Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation
packagist
kimai/kimai
Moderate
10 days ago
Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized Visibility
packagist
kimai/kimai
Critical
10 days ago
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
packagist
kimai/kimai
Moderate
10 days ago
Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes
packagist
kimai/kimai
Moderate
10 days ago
Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation
packagist
kimai/kimai
Moderate
10 days ago
Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects
packagist
kimai/kimai
Moderate
10 days ago
Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass
packagist
kimai/kimai
Moderate
10 days ago
Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target
packagist
kimai/kimai
Moderate
10 days ago
Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes
packagist
kimai/kimai
Critical
10 days ago
FacturaScripts: Account takeover of any 2FA-enabled user
packagist
facturascripts/facturascripts
High
10 days ago
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
packagist
nukeviet/nukeviet
High
10 days ago
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
packagist
nukeviet/nukeviet
High
10 days ago
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
packagist
nukeviet/nukeviet
High
10 days ago
NukeViet: Unauthenticated Reflected XSS in Comment Module
packagist
nukeviet/nukeviet
Critical
13 days ago
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
packagist
prestashop/ps_facetedsearch
High
13 days ago
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
packagist
notrinos/notrinos-erp
Moderate
13 days ago
Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs
packagist
kimai/kimai
Moderate
13 days ago
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
packagist
api-platform/hal, api-platform/json-api, api-platform/core
Moderate
14 days ago
Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint
packagist
sylius/sylius
Moderate
14 days ago
Sylius: Cart FormComponent allows modification or deletion of an already-completed order
packagist
sylius/sylius
Critical
14 days ago
YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
packagist
yeswiki/yeswiki
Critical
14 days ago
YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize
packagist
yeswiki/yeswiki
High
14 days ago
YesWiki has Authenticated SQL Injection via ReactionManager
packagist
yeswiki/yeswiki
Moderate
14 days ago
YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes
packagist
yeswiki/yeswiki
Moderate
14 days ago
YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php`
packagist
yeswiki/yeswiki
Moderate
14 days ago
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html'))
packagist
yeswiki/yeswiki
High
14 days ago
YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)
packagist
yeswiki/yeswiki
High
14 days ago
YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters
packagist
yeswiki/yeswiki
High
14 days ago
YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
packagist
yeswiki/yeswiki
High
14 days ago
YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`
packagist
yeswiki/yeswiki
Critical
14 days ago
YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
packagist
yeswiki/yeswiki
Moderate
14 days ago
YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read
packagist
yeswiki/yeswiki
High
14 days ago
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
packagist
yeswiki/yeswiki
High
14 days ago
laravel-backup-restore has an OS Command Injection during database restore
packagist
wnx/laravel-backup-restore
Moderate
14 days ago
Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests
packagist
admidio/admidio
High
14 days ago
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
packagist
craftcms/cms
Low
14 days ago
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
packagist
craftcms/cms
Moderate
15 days ago
Sharp Missing Authorization Check in Quick Creation Command Endpoints
packagist
code16/sharp
Low
16 days ago
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
packagist
web-auth/webauthn-lib
Moderate
16 days ago
EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
packagist
egroupware/egroupware
High
16 days ago
EGroupware has Authenticated RCE via Malicious eTemplate Upload
packagist
egroupware/egroupware
Critical
16 days ago
EGroupware has a Remote Code Execution Vulnerability
packagist
egroupware/egroupware
High
17 days ago
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
packagist
craftcms/cms
Moderate
17 days ago
Craft CMS: Stored XSS via Structure entry title in table view
packagist
craftcms/cms
Moderate
17 days ago
Craft CMS: Sensitive File Disclosure / Server-Side File Read
packagist
craftcms/cms
High
17 days ago
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
packagist
craftcms/cms
Moderate
17 days ago
Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
packagist
craftcms/cms
Critical
17 days ago
Formie Hidden field defaults vulnerable to Server-Side Template Injection
packagist
verbb/formie
High
21 days ago
SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`
packagist
simplesamlphp/simplesamlphp
Low
21 days ago
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
packagist
kimai/kimai
High
21 days ago
SimpleSAMLphp has Possible DoS via XPath Transform
packagist
simplesamlphp/saml2-legacy, simplesamlphp/saml2
High
21 days ago
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
packagist
simplesamlphp/saml2-legacy, simplesamlphp/saml2
High
21 days ago
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
packagist
craftcms/cms
Filter by Severity
Filter by Package
moodle/moodle
437
magento/community-edition
361
typo3/cms
163
wwbn/avideo
144
pimcore/pimcore
132
dolibarr/dolibarr
126
concrete5/concrete5
120
typo3/cms-core
120
magento/project-community-edition
120
craftcms/cms
116
phpmyadmin/phpmyadmin
107
drupal/core
106
microweber/microweber
105
thorsten/phpmyfaq
104
librenms/librenms
100
symfony/symfony
91
silverstripe/framework
90
shopware/platform
74
mantisbt/mantisbt
74
drupal/drupal
71
getgrav/grav
69
shopware/core
65
mautic/core
57
snipe/snipe-it
57
baserproject/basercms
56
froxlor/froxlor
55
admidio/admidio
50
getkirby/cms
47
nilsteampassnet/teampass
42
showdoc/showdoc
42
intelliants/subrion
41
phpmyfaq/phpmyfaq
40
statamic/cms
37
ci4-cms-erp/ci4ms
36
shopware/shopware
33
kimai/kimai
33
zendframework/zendframework1
32
prestashop/prestashop
31
yeswiki/yeswiki
31
contao/core-bundle
31
pocketmine/pocketmine-mp
30
phpoffice/phpspreadsheet
29
mediawiki/core
28
centreon/centreon
27
cockpit-hq/cockpit
26
funadmin/funadmin
26
openmage/magento-lts
26
facturascripts/facturascripts
26
grumpydictator/firefly-iii
25
laravel/framework
25
twig/twig
24
magento/core
24
typo3/cms-backend
24
simplesamlphp/simplesamlphp
23
remdex/livehelperchat
23
zendframework/zendframework
22
october/system
22
tribalsystems/zenario
22
sylius/sylius
22
craftcms/commerce
21
feehi/cms
21
dompdf/dompdf
20
bagisto/bagisto
20
topthink/framework
19
cakephp/cakephp
19
contao/contao
19
forkcms/forkcms
18
genix/cms
18
pimcore/admin-ui-classic-bundle
17
opencart/opencart
17
yetiforce/yetiforce-crm
17
devcode-it/openstamanager
17
nukeviet/nukeviet
17
phpbb/phpbb
17
pterodactyl/panel
17
francoisjacquet/rosariosis
17
ec-cube/ec-cube
16
WWBN/AVideo
16
symfony/security-http
16
tinymce/tinymce
15
smarty/smarty
15
bolt/bolt
15
ezsystems/ezpublish-kernel
15
tinymce
15
silverstripe/cms
15
codeigniter4/framework
15
studio-42/elfinder
15
composer/composer
15
modx/revolution
14
TinyMCE
14
phpmailer/phpmailer
14
sulu/sulu
14
lavalite/cms
14
feehi/feehicms
14
alextselegidis/easyappointments
14
impresscms/impresscms
13
guzzlehttp/guzzle
13
redaxo/source
13
pagekit/pagekit
13
symfony/security
13
elefant/cms
13
leantime/leantime
12
october/october
12
symfony/http-foundation
12
yiisoft/yii2
12
wallabag/wallabag
12
ezsystems/ezpublish-legacy
11
croogo/croogo
10
spatie/browsershot
10
billz/raspap-webgui
10
phpseclib/phpseclib
10
ezsystems/ezplatform-admin-ui
10
roundcube/roundcubemail
10
ezsystems/ezplatform-kernel
10
ssddanbrown/bookstack
10
flarum/core
9
concrete5/core
9
in2code/femanager
9
contao/core
9
starcitizentools/citizen-skin
9
kevinpapst/kimai2
9
opensource-workshop/connect-cms
9
krayin/laravel-crm
9
simplesamlphp/saml2
9
in2code/powermail
9
pimcore/customer-management-framework-bundle
9
azuracast/azuracast
9
codiad/codiad
8
silverstripe/graphql
8
directmailteam/direct-mail
8
tecnickcom/tcpdf
8
gilacms/gila
8
joomla/joomla-cms
8
october/cms
8
phanan/koel
8
silverstripe/admin
8
symfony/http-kernel
8
vrana/adminer
8
backdrop/backdrop
8
unopim/unopim
7
passbolt/passbolt_api
7
getformwork/formwork
7
api-platform/core
7
shopxo/shopxo
7
yiisoft/yii2-dev
7
october/backend
7
egroupware/egroupware
7
verbb/formie
7
idno/known
7
wpglobus/wpglobus
7
yourls/yourls
7
symfony/ux-live-component
6
drupal/core-recommended
6
typo3/html-sanitizer
6
privatebin/privatebin
6
dweeves/magmi
6
auth0/wordpress
6
typo3/cms-install
6
oro/platform
6
october/rain
6
pear/archive_tar
6
icecoder/icecoder
6
guzzlehttp/psr7
6
limesurvey/limesurvey
6
typo3/cms-form
6
league/commonmark
6
processwire/processwire
6
ibexa/admin-ui
6
zoujingli/thinkadmin
6
paymenter/paymenter
6
adodb/adodb-php
6
auth0/symfony
6
gleez/cms
6
nystudio107/craft-seomatic
6
code16/sharp
6
auth0/auth0-php
5
illuminate/database
5
solspace/craft-freeform
5
silverstripe/assets
5
woocommerce/woocommerce
5
cachethq/cachet
5
symfony/html-sanitizer
5
phpservermon/phpservermon
5
elgg/elgg
5
symfony/security-core
5
phpxmlrpc/phpxmlrpc
5
bottelet/flarepoint
5
neos/flow
5
notrinos/notrinos-erp
5
phppgadmin/phppgadmin
5
anchorcms/anchor-cms
5
tpwd/ke_search
5
neos/neos
5
thinkcmf/thinkcmf
5
flightphp/core
5
mineadmin/mineadmin
5
automad/automad
5
auth0/login
5
shopper/framework
5
ibexa/core
5
Filter by Repository
https://github.com/moodle/moodle
250
https://github.com/pimcore/pimcore
116
https://github.com/TYPO3/typo3
93
https://github.com/microweber/microweber
90
https://github.com/librenms/librenms
77
https://github.com/thorsten/phpmyfaq
69
https://github.com/silverstripe/silverstripe-framework
68
https://github.com/symfony/symfony
64
https://github.com/Dolibarr/dolibarr
60
https://github.com/mautic/mautic
46
https://github.com/phpmyadmin/phpmyadmin
45
https://github.com/concretecms/concretecms
44
https://github.com/shopware/platform
42
https://github.com/mantisbt/mantisbt
42
https://github.com/craftcms/cms
41
https://github.com/shopware/shopware
40
https://github.com/star7th/showdoc
39
https://github.com/magento/magento2
38
https://github.com/octobercms/october
36
https://github.com/snipe/snipe-it
30
https://github.com/contao/contao
30
https://github.com/baserproject/basercms
26
https://github.com/froxlor/froxlor
26
https://github.com/pmmp/PocketMine-MP
25
https://github.com/getgrav/grav
24
https://github.com/TYPO3/TYPO3.CMS
23
https://github.com/livehelperchat/livehelperchat
23
https://github.com/nilsteampassnet/TeamPass
23
https://github.com/firefly-iii/firefly-iii
23
https://github.com/PrestaShop/PrestaShop
23
https://github.com/getkirby/kirby
22
https://github.com/PHPOffice/PhpSpreadsheet
22
https://github.com/laravel/framework
21
https://github.com/funadmin/funadmin
20
https://github.com/simplesamlphp/simplesamlphp
19
https://github.com/TYPO3-CMS/core
19
https://github.com/nilsteampassnet/teampass
19
https://github.com/intelliants/subrion
19
https://github.com/OpenMage/magento-lts
18
https://github.com/liufee/cms
17
https://github.com/yetiforcecompany/yetiforcecrm
16
https://github.com/forkcms/forkcms
16
https://github.com/PHPMailer/PHPMailer
15
https://github.com/drupal/core
15
https://github.com/dompdf/dompdf
15
https://github.com/thorsten/phpMyFAQ
15
https://github.com/centreon/centreon
15
https://github.com/zendframework/zendframework
15
https://github.com/pimcore/admin-ui-classic-bundle
14
https://github.com/cockpit-hq/cockpit
14
https://github.com/smarty-php/smarty
12
https://github.com/codeigniter4/CodeIgniter4
12
https://github.com/YesWiki/yeswiki
12
https://sourceforge.net/projects/phpmyadmin.sourceforge.net
12
https://github.com/yiisoft/yii2
12
https://github.com/modxcms/revolution
12
https://github.com/centreon/centreon-archived
12
https://github.com/Sylius/Sylius
11
https://github.com/tinymce/tinymce
11
https://github.com/top-think/framework
11
https://github.com/Leantime/leantime
11
https://github.com/WWBN/AVideo
11
https://github.com/cakephp/cakephp
11
https://github.com/sulu/sulu
11
https://github.com/dolibarr/dolibarr
11
https://github.com/Studio-42/elFinder
11
https://github.com/opencart/opencart
10
https://github.com/bolt/bolt
10
https://github.com/semplon/GeniXCMS
10
https://github.com/wallabag/wallabag
10
https://github.com/kevinpapst/kimai2
9
https://github.com/StarCitizenTools/mediawiki-skins-Citizen
9
https://github.com/LavaLite/cms
9
https://github.com/alextselegidis/easyappointments
9
https://github.com/neorazorx/facturascripts
9
https://github.com/ezsystems/ezpublish-kernel
9
https://github.com/bagisto/bagisto
9
https://github.com/spatie/browsershot
9
https://github.com/pterodactyl/panel
9
https://github.com/statamic/cms
9
https://github.com/francoisjacquet/rosariosis
8
https://github.com/admidio/admidio
8
https://github.com/twigphp/Twig
8
https://github.com/pimcore/customer-data-framework
8
https://github.com/GilaCMS/gila
8
https://github.com/ezsystems/ezplatform-admin-ui
8
https://github.com/TribalSystems/Zenario
8
https://github.com/croogo/croogo
8
https://github.com/Froxlor/Froxlor
8
https://github.com/tecnickcom/TCPDF
8
https://github.com/RaspAP/raspap-webgui
8
https://github.com/flarum/framework
8
https://github.com/passbolt/passbolt_api
7
https://github.com/d4wner/Vulnerabilities-Report
7
https://github.com/pagekit/pagekit
7
https://github.com/composer/composer
7
https://github.com/Codiad/Codiad
7
https://github.com/wintercms/winter
7
https://github.com/ezsystems/ezplatform-kernel
7
https://github.com/unopim/unopim
7
https://github.com/silverstripe/silverstripe-graphql
6
https://gitlab.com/francoisjacquet/rosariosis
6
https://github.com/auth0/auth0-PHP
6
https://github.com/ADOdb/ADOdb
6
https://github.com/vrana/adminer
6
https://github.com/Admidio/admidio
6
https://github.com/guzzle/guzzle
6
https://github.com/nystudio107/craft-seomatic
6
https://github.com/ezsystems/ezpublish-legacy
6
https://github.com/gleez/cms
6
https://github.com/oroinc/orocommerce
6
https://github.com/LimeSurvey/LimeSurvey
6
https://github.com/bookstackapp/bookstack
6
https://github.com/ImpressCMS/impresscms
6
https://github.com/api-platform/core
6
https://github.com/thinkcmf/thinkcmf
5
https://github.com/jbroadway/elefant
5
https://github.com/ibexa/admin-ui
5
https://github.com/nukeviet/nukeviet
5
https://github.com/shopware5/shopware
5
https://github.com/oroinc/platform
5
https://github.com/dub-flow/vulnerability-research
5
https://github.com/contao/core
5
https://github.com/Bottelet/DaybydayCRM
5
https://github.com/pear/Archive_Tar
5
https://github.com/zendframework/zf1
5
https://github.com/backdrop/backdrop
5
https://github.com/getformwork/formwork
5
https://github.com/gggeek/phpxmlrpc
5
https://github.com/ibexa/core
5
https://github.com/in2code-de/femanager
5
https://github.com/appwrite/appwrite
4
https://github.com/Cockpit-HQ/Cockpit
4
https://github.com/phpservermon/phpservermon
4
https://github.com/pixelfed/pixelfed
4
https://github.com/BookStackApp/BookStack
4
https://github.com/oroinc/crm
4
https://github.com/reportico-web/reportico
4
https://github.com/TYPO3/html-sanitizer
4
https://github.com/fiveai/Cachet
4
https://github.com/silverstripe/silverstripe-admin
4
https://github.com/hieuminhnv/Zenario-CMS-last-version
4
https://github.com/brefphp/bref
4
https://github.com/Sylius/SyliusResourceBundle
4
https://github.com/froxlor/Froxlor
4
https://github.com/kimai/kimai
4
https://github.com/ezsystems/ezplatform-richtext
4
https://github.com/zoujingli/ThinkAdmin
4
https://github.com/progprnv/CVE-Reports
4
https://github.com/livewire/livewire
4
https://github.com/GiacoLenzo2109/MoonShine_Software_PoCs
4
https://github.com/ezsystems/ezplatform
4
https://github.com/crater-invoice/crater
4
https://github.com/darylldoyle/svg-sanitizer
4
https://github.com/in2code-de/powermail
4
https://github.com/PrivateBin/PrivateBin
4
https://github.com/haxtheweb/issues
4
https://github.com/codeigniter4/shield
4
https://github.com/yourls/yourls
4
https://github.com/FriendsOfSymfony/FOSUserBundle
3
https://github.com/facade/ignition
3
https://github.com/joomla/joomla-cms
3
https://github.com/phpbb/phpbb-app
3
https://github.com/Athlon1600/php-proxy-app
3
https://github.com/Cyber-Wo0dy/report
3
https://github.com/liufee/feehicms
3
https://github.com/TYPO3-CMS/backend
3
https://github.com/verbb/comments
3
https://github.com/auth0/wordpress
3
https://github.com/ezsystems/ezplatform-http-cache
3
https://github.com/UniSharp/laravel-filemanager
3
https://github.com/wikimedia/mediawiki
3
https://github.com/qcubed/qcubed
3
https://github.com/TYPO3-Solr/ext-solr
3
https://github.com/nitsan-technologies/ns_backup
3
https://github.com/opensource-workshop/connect-cms
3
https://github.com/phpseclib/phpseclib
3
https://github.com/phpbb/phpbb
3
https://github.com/github/advisory-database
3
https://github.com/orchidsoftware/platform
3
https://github.com/dd3x3r/enhavo
3
https://github.com/uasoft-indonesia/badaso
3
https://github.com/grokability/snipe-it
3
https://github.com/ibexa/fieldtype-richtext
3
https://github.com/Sylius/PayPalPlugin
3
https://github.com/guzzle/psr7
3
https://github.com/woocommerce/woocommerce
3
https://github.com/redaxo/redaxo
3
https://github.com/torrentpier/torrentpier
3
https://github.com/uvdesk/community-skeleton
3
https://github.com/notrinos/notrinoserp
3
https://github.com/aimeos/ai-admin-graphql
3
https://github.com/elgg/elgg
3
https://github.com/flarum/core
3
https://github.com/thedevdojo/voyager
3
https://github.com/yiisoft/yii
3
https://github.com/thephpleague/commonmark
3
https://github.com/idno/known
3
https://github.com/PrestaShop/productcomments
3