packagist
Security Advisories in packagist
High
1 day ago
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
packagist
getgrav/grav
High
3 days ago
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
packagist
pimcore/pimcore
Moderate
4 days ago
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
packagist
thorsten/phpmyfaq
Moderate
4 days ago
LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment
packagist
librenms/librenms
High
4 days ago
Winter: Authenticated backend users can bypass Users controller permission checks
packagist
winter/wn-backend-module
Moderate
4 days ago
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
packagist
winter/wn-cms-module
Moderate
4 days ago
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
packagist
winter/wn-backend-module
High
4 days ago
Winter: Stored XSS through Editor Settings custom styles
packagist
winter/wn-backend-module
High
4 days ago
Winter: Stored XSS through Brand Settings custom styles
packagist
winter/wn-backend-module
Critical
8 days ago
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
packagist
codeigniter4/framework
High
8 days ago
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
packagist
codeigniter4/framework
Critical
8 days ago
CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
packagist
codeigniter4/framework
Moderate
8 days ago
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
packagist
codeigniter4/framework
Moderate
8 days ago
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
packagist
api-platform/core
Moderate
9 days ago
Smarty Security stream restriction bypass through stream: resource
packagist
smarty/smarty
Moderate
9 days ago
Smarty: Symlink path traversal out of trusted directories
packagist
smarty/smarty
Critical
9 days ago
Craft CMS: Passkey login accepts replayed WebAuthn assertions
packagist
craftcms/cms
Moderate
9 days ago
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
packagist
craftcms/cms
Moderate
9 days ago
Craft CMS: Authenticated leak of secret environment variables
packagist
craftcms/cms
Moderate
9 days ago
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
packagist
craftcms/cms
Moderate
9 days ago
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
packagist
craftcms/cms
Low
9 days ago
Craft CMS: Incorrect path validation could potentially lead to path traversal
packagist
craftcms/cms
Moderate
9 days ago
Craft CMS: Stored XSS in the control panel via unescaped draft name
packagist
craftcms/cms
High
9 days ago
PHP_CodeSniffer gitblame report command injection via crafted filename
packagist
squizlabs/php_codesniffer
High
9 days ago
Craft CMS: Arbitrary user password reset leading to administrator account takeover
packagist
craftcms/cms
Moderate
9 days ago
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
packagist
craftcms/cms
High
9 days ago
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
packagist
craftcms/cms
Moderate
9 days ago
league/commonmark: Denial of service via deeply nested XML output
packagist
league/commonmark
High
9 days ago
league/commonmark: Denial of service via colliding heading slugs
packagist
league/commonmark
High
9 days ago
league/commonmark: Denial of service via duplicate footnote definitions
packagist
league/commonmark
High
9 days ago
league/commonmark: Denial of service via adjacent inline attribute blocks
packagist
league/commonmark
High
9 days ago
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
packagist
league/commonmark
Moderate
9 days ago
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
packagist
league/commonmark
Low
9 days ago
Contao: Possible path traversal in job download URIs
packagist
contao/core-bundle, contao/contao
Low
9 days ago
Contao crawler leaks auth credentials to external hosts
packagist
contao/core-bundle, contao/contao
Moderate
9 days ago
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
packagist
statamic/cms
Moderate
9 days ago
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
packagist
statamic/cms
Moderate
9 days ago
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
packagist
statamic/cms
Moderate
9 days ago
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
packagist
statamic/cms
High
9 days ago
Statamic: Account takeover via OAuth email matching without email-verification check
packagist
statamic/cms
Moderate
9 days ago
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
packagist
statamic/cms
Moderate
12 days ago
Guzzle: Noncanonical cookie domain keeps subdomain scope
packagist
guzzlehttp/guzzle
Moderate
15 days ago
WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)
packagist
wp-graphql/wp-graphql
High
15 days ago
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
packagist
redaxo/source
Moderate
15 days ago
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
packagist
sylius/mollie-plugin
High
15 days ago
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
packagist
sylius/mollie-plugin
Low
17 days ago
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
packagist
alextselegidis/easyappointments
Low
17 days ago
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
packagist
alextselegidis/easyappointments
Moderate
17 days ago
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
packagist
alextselegidis/easyappointments
Low
18 days ago
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
packagist
alextselegidis/easyappointments
Low
18 days ago
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
packagist
alextselegidis/easyappointments
High
18 days ago
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
packagist
alextselegidis/easyappointments
Critical
18 days ago
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
packagist
poweradmin/poweradmin
High
19 days ago
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
go, packagist
github.com/pterodactyl/wings, pterodactyl/panel
High
19 days ago
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
packagist
pterodactyl/panel
High
19 days ago
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
packagist
wp-coding-standards/wpcs
High
22 days ago
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
packagist
poweradmin/poweradmin
High
22 days ago
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
packagist
poweradmin/poweradmin
High
22 days ago
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
packagist
poweradmin/poweradmin
Critical
22 days ago
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
packagist
pheditor/pheditor
High
22 days ago
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
packagist
pheditor/pheditor
High
24 days ago
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
packagist
phpoffice/phpspreadsheet
High
24 days ago
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
packagist
phpoffice/phpspreadsheet
High
24 days ago
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
packagist
phpoffice/phpspreadsheet
Moderate
24 days ago
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
packagist
dompdf/dompdf
Moderate
24 days ago
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
packagist
dompdf/dompdf
Moderate
24 days ago
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
packagist
dompdf/dompdf
Moderate
24 days ago
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
packagist
dompdf/dompdf
Low
24 days ago
Dompdf: File existence oracle via font-face stylesheet declaration
packagist
dompdf/dompdf
Moderate
25 days ago
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
packagist
guzzlehttp/psr7
Moderate
26 days ago
Guzzle: URI fragments disclosed in redirect Referer headers
packagist
guzzlehttp/guzzle
Moderate
26 days ago
Guzzle: Unbounded response cookies risk denial of service
packagist
guzzlehttp/guzzle
Moderate
26 days ago
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
packagist
guzzlehttp/guzzle
Moderate
26 days ago
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
packagist
composer/composer
Moderate
26 days ago
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
packagist
composer/composer
Moderate
26 days ago
Guzzle: Proxy-Authorization headers can be sent to origin servers
packagist
guzzlehttp/guzzle
High
26 days ago
Composer: Arbitrary file write outside vendor via malicious transitive package name
packagist
composer/composer
Moderate
29 days ago
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration
packagist
verbb/formie
Critical
about 1 month ago
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
packagist
pheditor/pheditor
High
about 1 month ago
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
packagist
pheditor/pheditor
High
about 1 month ago
Pheditor has an authenticated terminal command whitelist bypass
packagist
pheditor/pheditor
Moderate
about 1 month ago
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
packagist
adawolfa/isdoc
High
about 1 month ago
MantisBT: Stored XSS in print_all_bug_page_word.php
packagist
mantisbt/mantisbt
Moderate
about 1 month ago
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
packagist
mantisbt/mantisbt
Moderate
about 1 month ago
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
packagist
mantisbt/mantisbt
Critical
about 1 month ago
MantisBT: Reflected XSS in admin/install.php via unescaped printf
packagist
mantisbt/mantisbt
Moderate
about 1 month ago
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
packagist
phanan/koel
Moderate
about 1 month ago
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
packagist
phanan/koel
High
about 1 month ago
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths
packagist
phanan/koel
Moderate
about 1 month ago
Koel has SSRF through Authenticated Subsonic podcast feed URLs
packagist
phanan/koel
High
about 1 month ago
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations
packagist
phanan/koel
Moderate
about 1 month ago
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation
packagist
phanan/koel
Moderate
about 1 month ago
MantisBT: REST API unauthorized Issue status change
packagist
mantisbt/mantisbt
High
about 1 month ago
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
packagist
mantisbt/mantisbt
Filter by Severity
Filter by Package
moodle/moodle
437
magento/community-edition
361
typo3/cms
167
wwbn/avideo
144
pimcore/pimcore
133
craftcms/cms
127
dolibarr/dolibarr
126
concrete5/concrete5
121
typo3/cms-core
120
magento/project-community-edition
120
phpmyadmin/phpmyadmin
107
drupal/core
107
thorsten/phpmyfaq
106
microweber/microweber
105
librenms/librenms
101
silverstripe/framework
90
symfony/symfony
90
mantisbt/mantisbt
74
shopware/platform
74
drupal/drupal
72
getgrav/grav
70
shopware/core
64
snipe/snipe-it
57
mautic/core
57
baserproject/basercms
56
froxlor/froxlor
55
admidio/admidio
50
getkirby/cms
47
statamic/cms
43
showdoc/showdoc
42
nilsteampassnet/teampass
42
phpmyfaq/phpmyfaq
41
intelliants/subrion
41
ci4-cms-erp/ci4ms
36
shopware/shopware
33
kimai/kimai
33
contao/core-bundle
33
zendframework/zendframework1
32
phpoffice/phpspreadsheet
31
prestashop/prestashop
31
yeswiki/yeswiki
31
pocketmine/pocketmine-mp
30
mediawiki/core
28
centreon/centreon
27
openmage/magento-lts
26
cockpit-hq/cockpit
26
funadmin/funadmin
26
facturascripts/facturascripts
26
grumpydictator/firefly-iii
25
laravel/framework
25
twig/twig
24
typo3/cms-backend
23
simplesamlphp/simplesamlphp
23
remdex/livehelperchat
23
magento/core
23
october/system
22
tribalsystems/zenario
22
sylius/sylius
22
zendframework/zendframework
22
contao/contao
21
feehi/cms
21
craftcms/commerce
21
bagisto/bagisto
20
alextselegidis/easyappointments
20
dompdf/dompdf
20
pterodactyl/panel
19
codeigniter4/framework
19
topthink/framework
19
cakephp/cakephp
19
forkcms/forkcms
18
genix/cms
18
devcode-it/openstamanager
17
opencart/opencart
17
smarty/smarty
17
francoisjacquet/rosariosis
17
nukeviet/nukeviet
17
pimcore/admin-ui-classic-bundle
17
yetiforce/yetiforce-crm
17
phpbb/phpbb
17
symfony/security-http
16
WWBN/AVideo
16
ec-cube/ec-cube
16
silverstripe/cms
16
guzzlehttp/guzzle
15
ezsystems/ezpublish-kernel
15
bolt/bolt
15
studio-42/elfinder
15
composer/composer
15
phpmailer/phpmailer
14
feehi/feehicms
14
TinyMCE
14
lavalite/cms
14
sulu/sulu
14
tinymce
14
modx/revolution
14
tinymce/tinymce
14
redaxo/source
14
impresscms/impresscms
13
pagekit/pagekit
13
elefant/cms
13
wallabag/wallabag
12
october/october
12
symfony/http-foundation
12
leantime/leantime
12
league/commonmark
12
yiisoft/yii2
12
symfony/security
11
ezsystems/ezpublish-legacy
11
ezsystems/ezplatform-kernel
10
phpseclib/phpseclib
10
roundcube/roundcubemail
10
ssddanbrown/bookstack
10
ezsystems/ezplatform-admin-ui
10
billz/raspap-webgui
10
croogo/croogo
10
spatie/browsershot
10
azuracast/azuracast
9
contao/core
9
simplesamlphp/saml2
9
krayin/laravel-crm
9
opensource-workshop/connect-cms
9
flarum/core
9
concrete5/core
9
kevinpapst/kimai2
9
in2code/powermail
9
in2code/femanager
9
starcitizentools/citizen-skin
9
pimcore/customer-management-framework-bundle
9
october/cms
8
silverstripe/admin
8
directmailteam/direct-mail
8
silverstripe/graphql
8
limesurvey/limesurvey
8
tecnickcom/tcpdf
8
joomla/joomla-cms
8
vrana/adminer
8
codiad/codiad
8
phanan/koel
8
symfony/http-kernel
8
gilacms/gila
8
backdrop/backdrop
8
api-platform/core
8
winter/wn-backend-module
7
idno/known
7
shopxo/shopxo
7
yourls/yourls
7
verbb/formie
7
unopim/unopim
7
yiisoft/yii2-dev
7
october/backend
7
getformwork/formwork
7
passbolt/passbolt_api
7
wpglobus/wpglobus
7
egroupware/egroupware
7
pear/archive_tar
6
dweeves/magmi
6
typo3/html-sanitizer
6
drupal/core-recommended
6
code16/sharp
6
auth0/wordpress
6
privatebin/privatebin
6
adodb/adodb-php
6
icecoder/icecoder
6
nystudio107/craft-seomatic
6
typo3/cms-form
6
gleez/cms
6
paymenter/paymenter
6
pheditor/pheditor
6
ibexa/admin-ui
6
oro/platform
6
processwire/processwire
6
zoujingli/thinkadmin
6
october/rain
6
symfony/ux-live-component
6
guzzlehttp/psr7
6
typo3/cms-install
6
auth0/symfony
6
auth0/auth0-php
5
neos/neos
5
symfony/html-sanitizer
5
ibexa/core
5
symfony/yaml
5
auth0/login
5
mineadmin/mineadmin
5
phpservermon/phpservermon
5
elgg/elgg
5
gugoan/economizzer
5
tpwd/ke_search
5
solspace/craft-freeform
5
flightphp/core
5
bottelet/flarepoint
5
woocommerce/woocommerce
5
cachethq/cachet
5
symfony/security-core
5
neos/flow
5
thinkcmf/thinkcmf
5
phpxmlrpc/phpxmlrpc
5
phppgadmin/phppgadmin
5
juzaweb/cms
5
tcg/voyager
5
Filter by Repository
https://github.com/moodle/moodle
250
https://github.com/pimcore/pimcore
116
https://github.com/TYPO3/typo3
93
https://github.com/microweber/microweber
90
https://github.com/librenms/librenms
77
https://github.com/thorsten/phpmyfaq
69
https://github.com/silverstripe/silverstripe-framework
68
https://github.com/symfony/symfony
64
https://github.com/Dolibarr/dolibarr
60
https://github.com/mautic/mautic
46
https://github.com/phpmyadmin/phpmyadmin
45
https://github.com/concretecms/concretecms
44
https://github.com/mantisbt/mantisbt
42
https://github.com/shopware/platform
42
https://github.com/craftcms/cms
41
https://github.com/shopware/shopware
40
https://github.com/star7th/showdoc
39
https://github.com/magento/magento2
38
https://github.com/octobercms/october
36
https://github.com/snipe/snipe-it
30
https://github.com/contao/contao
30
https://github.com/baserproject/basercms
26
https://github.com/froxlor/froxlor
26
https://github.com/pmmp/PocketMine-MP
25
https://github.com/getgrav/grav
24
https://github.com/firefly-iii/firefly-iii
23
https://github.com/nilsteampassnet/TeamPass
23
https://github.com/PrestaShop/PrestaShop
23
https://github.com/TYPO3/TYPO3.CMS
23
https://github.com/livehelperchat/livehelperchat
23
https://github.com/PHPOffice/PhpSpreadsheet
22
https://github.com/getkirby/kirby
22
https://github.com/laravel/framework
21
https://github.com/funadmin/funadmin
20
https://github.com/intelliants/subrion
19
https://github.com/nilsteampassnet/teampass
19
https://github.com/TYPO3-CMS/core
19
https://github.com/simplesamlphp/simplesamlphp
19
https://github.com/OpenMage/magento-lts
18
https://github.com/liufee/cms
17
https://github.com/forkcms/forkcms
16
https://github.com/yetiforcecompany/yetiforcecrm
16
https://github.com/centreon/centreon
15
https://github.com/drupal/core
15
https://github.com/dompdf/dompdf
15
https://github.com/thorsten/phpMyFAQ
15
https://github.com/zendframework/zendframework
15
https://github.com/PHPMailer/PHPMailer
15
https://github.com/cockpit-hq/cockpit
14
https://github.com/pimcore/admin-ui-classic-bundle
14
https://github.com/yiisoft/yii2
12
https://sourceforge.net/projects/phpmyadmin.sourceforge.net
12
https://github.com/YesWiki/yeswiki
12
https://github.com/centreon/centreon-archived
12
https://github.com/modxcms/revolution
12
https://github.com/codeigniter4/CodeIgniter4
12
https://github.com/smarty-php/smarty
12
https://github.com/dolibarr/dolibarr
11
https://github.com/WWBN/AVideo
11
https://github.com/sulu/sulu
11
https://github.com/Leantime/leantime
11
https://github.com/top-think/framework
11
https://github.com/Studio-42/elFinder
11
https://github.com/cakephp/cakephp
11
https://github.com/Sylius/Sylius
11
https://github.com/semplon/GeniXCMS
10
https://github.com/opencart/opencart
10
https://github.com/wallabag/wallabag
10
https://github.com/tinymce/tinymce
10
https://github.com/bolt/bolt
10
https://github.com/neorazorx/facturascripts
9
https://github.com/kevinpapst/kimai2
9
https://github.com/bagisto/bagisto
9
https://github.com/statamic/cms
9
https://github.com/spatie/browsershot
9
https://github.com/pterodactyl/panel
9
https://github.com/LavaLite/cms
9
https://github.com/StarCitizenTools/mediawiki-skins-Citizen
9
https://github.com/ezsystems/ezpublish-kernel
9
https://github.com/alextselegidis/easyappointments
9
https://github.com/twigphp/Twig
8
https://github.com/Froxlor/Froxlor
8
https://github.com/tecnickcom/TCPDF
8
https://github.com/ezsystems/ezplatform-admin-ui
8
https://github.com/RaspAP/raspap-webgui
8
https://github.com/GilaCMS/gila
8
https://github.com/francoisjacquet/rosariosis
8
https://github.com/pimcore/customer-data-framework
8
https://github.com/croogo/croogo
8
https://github.com/TribalSystems/Zenario
8
https://github.com/admidio/admidio
8
https://github.com/flarum/framework
8
https://github.com/Codiad/Codiad
7
https://github.com/unopim/unopim
7
https://github.com/d4wner/Vulnerabilities-Report
7
https://github.com/composer/composer
7
https://github.com/wintercms/winter
7
https://github.com/passbolt/passbolt_api
7
https://github.com/ezsystems/ezplatform-kernel
7
https://github.com/pagekit/pagekit
7
https://github.com/guzzle/guzzle
6
https://github.com/auth0/auth0-PHP
6
https://github.com/silverstripe/silverstripe-graphql
6
https://github.com/ADOdb/ADOdb
6
https://github.com/api-platform/core
6
https://github.com/vrana/adminer
6
https://github.com/nystudio107/craft-seomatic
6
https://github.com/ezsystems/ezpublish-legacy
6
https://github.com/oroinc/orocommerce
6
https://github.com/gleez/cms
6
https://github.com/Admidio/admidio
6
https://github.com/ImpressCMS/impresscms
6
https://github.com/bookstackapp/bookstack
6
https://github.com/LimeSurvey/LimeSurvey
6
https://gitlab.com/francoisjacquet/rosariosis
6
https://github.com/ibexa/admin-ui
5
https://github.com/in2code-de/femanager
5
https://github.com/pear/Archive_Tar
5
https://github.com/contao/core
5
https://github.com/gggeek/phpxmlrpc
5
https://github.com/dub-flow/vulnerability-research
5
https://github.com/Bottelet/DaybydayCRM
5
https://github.com/ibexa/core
5
https://github.com/zendframework/zf1
5
https://github.com/oroinc/platform
5
https://github.com/getformwork/formwork
5
https://github.com/jbroadway/elefant
5
https://github.com/shopware5/shopware
5
https://github.com/nukeviet/nukeviet
5
https://github.com/thinkcmf/thinkcmf
5
https://github.com/backdrop/backdrop
5
https://github.com/in2code-de/powermail
4
https://github.com/appwrite/appwrite
4
https://github.com/zoujingli/ThinkAdmin
4
https://github.com/Sylius/SyliusResourceBundle
4
https://github.com/hieuminhnv/Zenario-CMS-last-version
4
https://github.com/progprnv/CVE-Reports
4
https://github.com/froxlor/Froxlor
4
https://github.com/yourls/yourls
4
https://github.com/codeigniter4/shield
4
https://github.com/fiveai/Cachet
4
https://github.com/pixelfed/pixelfed
4
https://github.com/phpservermon/phpservermon
4
https://github.com/ezsystems/ezplatform
4
https://github.com/reportico-web/reportico
4
https://github.com/silverstripe/silverstripe-admin
4
https://github.com/Cockpit-HQ/Cockpit
4
https://github.com/GiacoLenzo2109/MoonShine_Software_PoCs
4
https://github.com/darylldoyle/svg-sanitizer
4
https://github.com/haxtheweb/issues
4
https://github.com/TYPO3/html-sanitizer
4
https://github.com/ezsystems/ezplatform-richtext
4
https://github.com/oroinc/crm
4
https://github.com/brefphp/bref
4
https://github.com/BookStackApp/BookStack
4
https://github.com/PrivateBin/PrivateBin
4
https://github.com/crater-invoice/crater
4
https://github.com/kimai/kimai
4
https://github.com/livewire/livewire
4
https://github.com/PrestaShop/productcomments
3
https://github.com/liufee/feehicms
3
https://github.com/concrete5/concrete5
3
https://github.com/torrentpier/torrentpier
3
https://github.com/elgg/elgg
3
https://github.com/thephpleague/commonmark
3
https://github.com/artesaos/seotools
3
https://github.com/Athlon1600/php-proxy-app
3
https://github.com/uvdesk/community-skeleton
3
https://github.com/ezsystems/ezplatform-http-cache
3
https://github.com/verbb/formie
3
https://github.com/PrestaShopCorp/ps_checkout
3
https://github.com/aimeos/ai-admin-graphql
3
https://github.com/phpbb/phpbb
3
https://github.com/idno/known
3
https://github.com/Sylius/PayPalPlugin
3
https://github.com/dd3x3r/enhavo
3
https://github.com/flarum/core
3
https://github.com/woocommerce/woocommerce
3
https://github.com/ibexa/fieldtype-richtext
3
https://github.com/uasoft-indonesia/badaso
3
https://github.com/orchidsoftware/platform
3
https://github.com/grokability/snipe-it
3
https://github.com/thedevdojo/voyager
3
https://github.com/FriendsOfSymfony/FOSUserBundle
3
https://github.com/redaxo/redaxo
3
https://github.com/github/advisory-database
3
https://github.com/alexbsec/CVEs
3
https://github.com/joomla/joomla-cms
3
https://github.com/phpseclib/phpseclib
3
https://github.com/quickapps/cms
3
https://github.com/facade/ignition
3
https://github.com/xjzzzxx/vulFound
3
https://github.com/phpbb/phpbb-app
3
https://github.com/yiisoft/yii
3
https://github.com/guzzle/psr7
3
https://github.com/wikimedia/mediawiki
3
https://github.com/auth0/wordpress
3
https://github.com/UniSharp/laravel-filemanager
3
https://github.com/belong2yourself/vulnerabilities
3