packagist
472,120 packages · packagist.org
Critical Security Advisories in packagist Clear Filters
Critical
over 1 year ago
codeigniter/framework SQL injection in ODBC database driver
packagist
codeigniter/framework
Critical
over 1 year ago
PrestaShop cross-site scripting via customer contact form in FO, through file upload
packagist
prestashop/prestashop
Critical
over 1 year ago
Cockpit CMS contains an arbitrary file upload vulenrability
packagist
cockpit-hq/cockpit
Critical
over 1 year ago
Blind XSS Leading to Froxlor Application Compromise
packagist
froxlor/froxlor
Critical
over 1 year ago
Zenario uses Twig filters insecurely in the Twig Snippet plugin
packagist
tribalsystems/zenario
Critical
over 1 year ago
PHPECC vulnerable to multiple cryptographic side-channel attacks
packagist
mdanter/ecc
Critical
over 1 year ago
Zend Framework SQL injection vulnerability
packagist
zendframework/zendframework, zendframework/zend-db, zendframework/zendframework1
Critical
over 1 year ago
Drupal Core Remote Code Execution Vulnerability
packagist
drupal/drupal, drupal/core
Critical
over 1 year ago
Gleez Cms Server Side Request Forgery (SSRF) vulnerability
packagist
gleez/cms
Critical
over 1 year ago
Remote Code Execution by uploading a phar file using frontmatter
packagist
getgrav/grav
Critical
over 1 year ago
Shopware's session is persistent in Cache for 404 pages
packagist
shopware/platform, shopware/storefront
Critical
over 1 year ago
Dompdf's usage of vulnerable version of phenx/php-svg-lib leads to restriction bypass and potential RCE
packagist
phenx/php-svg-lib
Critical
over 1 year ago
Deserialization of Untrusted Data in Torrentpier
packagist
torrentpier/torrentpier
Critical
over 1 year ago
Pixelfed doesn't check OAuth Scopes in API routes, giving elevated permissions
packagist
pixelfed/pixelfed
Critical
almost 2 years ago
Blind SQL injection in shopware
packagist
shopware/platform, shopware/core
Critical
almost 2 years ago
plotly.js prototype pollution vulnerability
npm, packagist
plotly.js, plotly/plotly.js
Critical
almost 2 years ago
PHPMemcachedAdmin Path Traversal vulnerability
packagist
elijaa/phpmemcacheadmin
Critical
almost 2 years ago
October CMS safe mode bypass using Twig sandbox escape
packagist
october/system
Critical
almost 2 years ago
Froxlor Improper Input Validation vulnerability
packagist
froxlor/froxlor
Critical
almost 2 years ago
Json response for search reveals Solr credentials
packagist
ezsystems/ezplatform-solr-search-engine
Critical
about 2 years ago
Cachet vulnerable to Authenticated Remote Code Execution
packagist
cachethq/cachet
Critical
about 2 years ago
Yii2 allows attackers to execute any local .php file via a relative path in the view parameter
packagist
yiisoft/yii2
Critical
about 2 years ago
Cross Site Scripting vulnerability in Dolibarr ERP CRM
packagist
dolibarr/dolibarr
Critical
about 2 years ago
Cockpit PHP Remote File Inclusion vulnerability
packagist
cockpit-hq/cockpit
Critical
over 2 years ago
Froxlor vulnerable to Improper Encoding or Escaping of Output
packagist
froxlor/froxlor
Critical
over 2 years ago
Orchid Deserialization of Untrusted Data vulnerability leads to Remote Code Execution
packagist
orchid/platform
Critical
over 2 years ago
php-imap vulnerable to RCE through a directory traversal vulnerability
packagist
webklex/laravel-imap, webklex/php-imap
Critical
over 2 years ago
Grav Server Side Template Injection (SSTI) vulnerability
packagist
getgrav/grav
Critical
over 2 years ago
Froxlor vulnerable to Improper Restriction of Excessive Authentication Attempts
packagist
froxlor/froxlor
Critical
over 2 years ago
TeamPass vulnerable to stored Cross-site Scripting
packagist
nilsteampassnet/teampass
Critical
over 2 years ago
Remote Code Execution Vulnerability in Validation Placeholders in CodeIgniter4
packagist
codeigniter4/framework
Critical
over 2 years ago
Concrete CMS (previously concrete5) is vulnerable to possible auth bypass in the jobs section
packagist
concrete5/concrete5
Critical
over 2 years ago
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
packagist
prestashop/prestashop
Critical
over 2 years ago
froxlor/froxlor vulnerable to unrestricted upload of file with dangerous type
packagist
froxlor/froxlor
Critical
over 2 years ago
X-Forwarded-For header allows brute-forcing autoblocked IP addresses
packagist
mediawiki/core
Critical
over 2 years ago
Moodle's Mustache pix helper contained a potential Mustache injection risk if combined with user input
packagist
moodle/moodle
Critical
over 2 years ago
baserCMS File Uploader Remote Code Execution (RCE) vulnerability
packagist
baserproject/basercms
Critical
over 2 years ago
PHAR deserialization allowing remote code execution
packagist
knplabs/knp-snappy
Critical
over 2 years ago
Access control issue in ezsystems/ezpublish-kernel
packagist
ezsystems/ezpublish-kernel
Critical
over 2 years ago
Easy!Appointments uses hard-coded credentials
packagist
alextselegidis/easyappointments
Critical
over 2 years ago
SQL injection in webbuilders-group silverstripe-kapost-bridge
packagist
webbuilders-group/silverstripe-kapost-bridge
Critical
over 2 years ago
URI validation failure on SVG parsing. Bypass of CVE-2023-23924
packagist
dompdf/dompdf
Critical
over 2 years ago
tinymighty WikiSEO is vulnerable to cross-site scripting via modifyHTML function
packagist
tinymighty/wiki-seo
Critical
almost 3 years ago
AVideo contains Command injection when embedding a video link
packagist
wwbn/avideo
Critical
almost 3 years ago
Dompdf vulnerable to URI validation failure on SVG parsing
packagist
dompdf/dompdf
Critical
almost 3 years ago
phpmyadmin contains SQL Injection vulnerability
packagist
phpmyadmin/phpmyadmin
Critical
almost 3 years ago
XpressEngine vulnerable to Unrestricted Upload of File with Dangerous Type
packagist
xpressengine/xpressengine
Critical
almost 3 years ago
CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection
packagist
cakephp/cakephp
Critical
almost 3 years ago
Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views
packagist
shopware/core, shopware/platform
Critical
almost 3 years ago
phpMyFAQ Improper Authentication vulnerability
packagist
thorsten/phpmyfaq
Critical
almost 3 years ago
PaginationServiceProvider SQL Injection vulnerability
packagist
ttskch/pagination-service-provider
Critical
almost 3 years ago
kelvinmo simplexrd vulnerable to Improper Restriction of XML External Entity Reference
packagist
kelvinmo/simplexrd
Critical
almost 3 years ago
himiklab yii2-jqgrid-widget vulnerable to SQL Injection
packagist
himiklab/yii2-jqgrid-widget
Critical
almost 3 years ago
DBRisinajumi d2files SQL Injection vulnerability
packagist
dbrisinajumi/d2files
Critical
almost 3 years ago
Ariadne Component Library vulnerable to Server-Side Request Forgery
packagist
arc/web
Critical
almost 3 years ago
ThinkPHP Framework vulnerable to remote code execution
packagist
topthink/framework
Critical
almost 3 years ago
laravel-jqgrid vulnerable to SQL Injection
packagist
mgallegos/laravel-jqgrid
Filter by Severity
Filter by Package
magento/community-edition
25
dolibarr/dolibarr
25
magento/project-community-edition
16
moodle/moodle
16
topthink/framework
15
drupal/core
12
phpmyadmin/phpmyadmin
10
funadmin/funadmin
9
drupal/drupal
9
froxlor/froxlor
8
shopware/platform
8
zendframework/zendframework1
7
studio-42/elfinder
7
symfony/symfony
7
thorsten/phpmyfaq
6
mautic/core
6
nilsteampassnet/teampass
6
zendframework/zendframework
6
typo3/cms
6
ezsystems/ezpublish-kernel
6
craftcms/cms
6
centreon/centreon
5
shopware/core
5
dompdf/dompdf
5
librenms/librenms
5
adodb/adodb-php
5
prestashop/prestashop
5
shopware/shopware
4
feehi/cms
4
contao/contao
4
showdoc/showdoc
4
nukeviet/nukeviet
4
simplesamlphp/simplesamlphp
4
tribalsystems/zenario
4
baserproject/basercms
4
codeigniter4/framework
3
wwbn/avideo
3
elefant/cms
3
symfony/security
3
codeigniter/framework
3
symfony/security-core
3
pimcore/pimcore
3
facade/ignition
3
ibexa/core
3
ezsystems/ezplatform-kernel
3
codiad/codiad
3
contao/core-bundle
3
smarty/smarty
3
silverstripe/framework
3
alextselegidis/easyappointments
3
phpmailer/phpmailer
3
impresscms/impresscms
3
francoisjacquet/rosariosis
3
ibexa/admin-ui
2
genix/cms
2
magento/core
2
qcubed/qcubed
2
shopxo/shopxo
2
knplabs/knp-snappy
2
billz/raspap-webgui
2
cockpit-hq/cockpit
2
nystudio107/craft-seomatic
2
zoujingli/thinkadmin
2
topthink/think
2
laravel/framework
2
openmage/magento-lts
2
admidio/admidio
2
auth0/auth0-php
2
flarum/core
2
mediawiki/core
2
islandora/crayfish
2
swiftmailer/swiftmailer
2
contao/core
2
verot/class.upload.php
2
badaso/core
2
getgrav/grav
2
auth0/login
2
tcg/voyager
2
ezsystems/ezplatform-admin-ui
2
pagekit/pagekit
2
facturascripts/facturascripts
2
intelliants/subrion
2
yiisoft/yii2
2
auth0/wordpress
2
torrentpier/torrentpier
2
pyrocms/pyrocms
2
typo3/phar-stream-wrapper
2
firebase/php-jwt
2
auth0/symfony
2
vufind/vufind
2
spiral/roadrunner
1
cakephp/cakephp
1
kimai/kimai
1
topthink/thinkphp
1
prestashop/ps_checkout
1
verbb/knock-knock
1
typo3/cms-core
1
zendframework/zend-xmlrpc
1
sylius/resource-bundle
1
usmanhalalit/pixie
1
rudloff/rtmpdump-bin
1
livewire/livewire
1
brightlocal/phpwhois
1
matyhtf/framework
1
webpa/webpa
1
bcit-ci/codeigniter
1
contao/listing-bundle
1
fenom/fenom
1
symfony/dependency-injection
1
silverstripe/cms
1
tecnickcom/tcpdf
1
roundcube/roundcubemail
1
pixelfed/pixelfed
1
apache-solr-for-typo3/solr
1
bedita/bedita
1
wp-cli/wp-cli
1
cesnet/simplesamlphp-module-proxystatistics
1
simple-updates/phpwhois
1
silverstripe/registry
1
filament/infolists
1
barrelstrength/sprout-forms
1
arc/web
1
vanilla/safecurl
1
yiisoft/yii2-dev
1
melisplatform/melis-cms-slider
1
terminal42/contao-tablelookupwizard
1
zendframework/zend-json
1
mikehaertl/php-shellcommand
1
willdurand/js-translation-bundle
1
ezsystems/repository-forms
1
ezsystems/ezplatform-solr-search-engine
1
simplesamlphp/saml2
1
joomla/joomla-cms
1
socialiteproviders/steam
1
catfan/medoo
1
neos/swiftmailer
1
fineuploader/php-traditional-server
1
magneto/core
1
akeneo/pim-community-dev
1
sabberworm/php-css-parser
1
ivankristianto/phpwhois
1
neorazorx/facturascripts
1
simogeo/filemanager
1
gree/jose
1
azuracast/azuracast
1
zendframework/zend-db
1
rmccue/requests
1
league/flysystem
1
symfony/serializer
1
impresspages/impresspages
1
mdanter/ecc
1
elijaa/phpmemcacheadmin
1
bacula-web/bacula-web
1
fluidtypo3/vhs
1
yiisoft/yii2-redis
1
tinymighty/wiki-seo
1
lavalite/cms
1
bagisto/bagisto
1
plotly.js
1
webklex/laravel-imap
1
xpressengine/xpressengine
1
ibexa/solr
1
web-auth/webauthn-framework
1
spoon/library
1
in2code/lux
1
barrelstrength/sprout-base-email
1
pterodactyl/panel
1
symfony/cache
1
filament/tables
1
october/rain
1
mgallegos/laravel-jqgrid
1
bmarshall511/wordpress_zero_spam
1
sjbr/sr-feuser-register
1
himiklab/yii2-jqgrid-widget
1
melisplatform/melis-cms
1
joomla/input
1
rankmath/seo-by-rank-math
1
namshi/jose
1
latte/latte
1
phpoffice/common
1
contao/managed-edition
1
silverstripe/restfulserver
1
bcosca/fatfree
1
doctrine/orm
1
webklex/php-imap
1
zendesk/zendesk_api_client_php
1
solspace/craft-freeform
1
phpunit/phpunit
1
pear/archive_tar
1
ezsystems/ezpublish-legacy
1
truckersmp/phpwhois
1
liftkit/database
1
appwrite/server-ce
1
serluck/phpwhois
1
litespeed.js
1
october/october
1
webbuilders-group/silverstripe-kapost-bridge
1
zendframework/zend-mail
1
open-web-analytics/open-web-analytics
1
islandora/islandora
1
Filter by Repository
https://github.com/Dolibarr/dolibarr
15
https://github.com/magento/magento2
10
https://github.com/funadmin/funadmin
9
https://github.com/top-think/framework
9
https://github.com/Studio-42/elFinder
7
https://github.com/symfony/symfony
7
https://github.com/shopware/platform
6
https://github.com/thorsten/phpmyfaq
6
https://github.com/dompdf/dompdf
6
https://github.com/craftcms/cms
5
https://github.com/auth0/auth0-PHP
5
https://github.com/froxlor/froxlor
5
https://github.com/PrestaShop/PrestaShop
5
https://github.com/moodle/moodle
5
https://github.com/ADOdb/ADOdb
5
https://github.com/star7th/showdoc
4
https://github.com/nilsteampassnet/TeamPass
4
https://github.com/mautic/mautic
4
https://github.com/liufee/cms
4
https://github.com/ezsystems/ezpublish-kernel
4
https://github.com/phpmyadmin/phpmyadmin
4
https://github.com/contao/contao
4
https://github.com/smarty-php/smarty
3
https://github.com/codeigniter4/CodeIgniter4
3
https://github.com/facade/ignition
3
https://github.com/librenms/librenms
3
https://github.com/baserproject/basercms
3
https://github.com/jbroadway/elefant
3
https://github.com/ImpressCMS/impresscms
3
https://github.com/ibexa/core
3
https://github.com/centreon/centreon-archived
3
https://github.com/shopware/shopware
3
https://github.com/PHPMailer/PHPMailer
3
https://github.com/pimcore/pimcore
3
https://github.com/neorazorx/facturascripts
3
https://github.com/simplesamlphp/simplesamlphp
3
https://github.com/TribalSystems/Zenario
3
https://github.com/octobercms/october
3
https://github.com/ezsystems/ezplatform-kernel
3
https://github.com/shopware5/shopware
3
https://github.com/nukeviet/nukeviet
3
https://github.com/semplon/GeniXCMS
2
https://github.com/torrentpier/torrentpier
2
https://github.com/qcubed/qcubed
2
https://gitlab.com/francoisjacquet/rosariosis
2
https://github.com/uasoft-indonesia/badaso
2
https://github.com/alextselegidis/easyappointments
2
https://github.com/vufind-org/vufind
2
https://github.com/RaspAP/raspap-webgui
2
https://github.com/Froxlor/Froxlor
2
https://github.com/zoujingli/ThinkAdmin
2
https://github.com/joomla/joomla-cms
2
https://github.com/Codiad/Codiad
2
https://github.com/ezsystems/ezplatform-admin-ui
2
https://github.com/silverstripe/silverstripe-framework
2
https://github.com/intelliants/subrion
2
https://github.com/firebase/php-jwt
2
https://github.com/OpenMage/magento-lts
2
https://github.com/Islandora/Crayfish
2
https://github.com/centreon/centreon
2
https://github.com/swiftmailer/swiftmailer
2
https://github.com/zendframework/zendframework
2
https://github.com/ibexa/admin-ui
2
https://github.com/cockpit-hq/cockpit
2
https://github.com/getgrav/grav
2
https://github.com/KnpLabs/snappy
2
https://github.com/nystudio107/craft-seomatic
2
https://github.com/Admidio/admidio
2
https://github.com/WWBN/AVideo
2
https://github.com/top-think/thinkphp
2
https://github.com/drupal/core
2
https://github.com/nilsteampassnet/teampass
2
https://github.com/TYPO3/phar-stream-wrapper
2
https://github.com/dolibarr/dolibarr
1
https://github.com/melisplatform/melis-cms-slider
1
https://github.com/vanilla/safecurl
1
https://github.com/lishihihi/voyager-issue-report
1
https://github.com/fenom-template/fenom
1
https://github.com/zendframework/zend-xmlrpc
1
https://github.com/sebastianbergmann/phpunit
1
https://github.com/wp-cli/wp-cli
1
https://github.com/usmanhalalit/pixie
1
https://github.com/a2u/CVE-2018-7600
1
https://github.com/LavaLite/cms
1
https://github.com/kelvinmo/simplexrd
1
https://github.com/CESNET/proxystatistics-simplesamlphp-module
1
https://github.com/auth0/laravel-auth0
1
https://github.com/tinymighty/wiki-seo
1
https://github.com/bcosca/fatfree-core
1
https://github.com/SocialiteProviders/Steam
1
https://github.com/livewire/volt
1
https://github.com/filamentphp/filament
1
https://github.com/yiisoft/yii2
1
https://github.com/Open-Web-Analytics/Open-Web-Analytics
1
https://github.com/ezsystems/ezplatform-solr-search-engine
1
https://github.com/pixelfed/pixelfed
1
https://github.com/verbb/knock-knock
1
https://github.com/saleem-hadad/larecipe
1
https://github.com/mgallegos/laravel-jqgrid
1
https://github.com/gleez/cms
1
https://github.com/twothink/twothink
1
https://github.com/Islandora/islandora
1
https://github.com/orchidsoftware/platform
1
https://github.com/flarum/framework
1
https://github.com/willdurand/BazingaJsTranslationBundle
1
https://github.com/jra89/CVE-2019-19634
1
https://github.com/plotly/plotly.js
1
https://github.com/jsmitty12/phpWhois
1
https://github.com/anchorcms/anchor-cms
1
https://github.com/auth0/wordpress
1
https://github.com/Ariadne-CMS/arc-web
1
https://github.com/terminal42/contao-tablelookupwizard
1
https://github.com/Sylius/SyliusGridBundle
1
https://github.com/flarum/core
1
https://github.com/froxlor/Froxlor
1
https://github.com/nonfiction/nterchange_backend
1
https://github.com/zendesk/zendesk_api_client_php
1
https://github.com/hhxsv5/laravel-s
1
https://github.com/akeneo/pim-community-dev
1
https://github.com/forkcms/library
1
https://github.com/Jasig/phpCAS
1
https://github.com/bedita/bedita
1
https://github.com/nette/latte
1
https://github.com/webbuilders-group/silverstripe-kapost-bridge
1
https://github.com/kohana/core
1
https://github.com/fru1ts/CVE-2024-44902
1
https://github.com/kimai/kimai
1
https://github.com/roundcube/roundcubemail
1
https://github.com/ttskch/PaginationServiceProvider
1
https://github.com/propelorm/Propel2
1
https://github.com/PHPOffice/PHPWord
1
https://github.com/titon/framework
1
https://github.com/liftkit/database
1
https://github.com/laminas/laminas-http
1
https://github.com/melisplatform/melis-core
1
https://github.com/ezsystems/repository-forms
1
https://github.com/roadrunner-server/roadrunner
1
https://github.com/top-think/think
1
https://github.com/paragonie/phpecc
1
https://github.com/Sylius/SyliusResourceBundle
1
https://github.com/JCCD/Contao-Managed-Edition-1.5-RCE
1
https://github.com/WangYihang/Codiad-Remote-Code-Execute-Exploit
1
https://github.com/pagekit/pagekit
1
https://github.com/nukeviet/module-shops
1
https://github.com/dweeves/magmi-git
1
https://github.com/Highfivery/zero-spam-for-wordpress
1
https://github.com/h4ckdepy/vuls
1
https://github.com/Rudloff/alltube
1
https://github.com/bihor/fp_newsletter
1
https://github.com/appwrite/appwrite
1
https://github.com/marshmallow-packages/nova-tiptap
1
https://github.com/mikehaertl/php-shellcommand
1
https://github.com/ibexa/graphql
1
https://github.com/cakephp/cakephp
1
https://github.com/WordPress/Requests
1
https://github.com/FriendsOfTYPO3/mediace
1
https://github.com/dota-st/Vulnerability
1
https://github.com/propelorm/Propel
1
https://github.com/TYPO3-Solr/ext-solr
1
https://github.com/doctrine/dbal
1
https://github.com/francoisjacquet/rosariosis
1
https://github.com/livewire/livewire
1
https://github.com/youncyb/dolibarr-rce
1
https://github.com/matyhtf/framework
1
https://github.com/bacula-web/bacula-web
1
https://github.com/bagisto/bagisto
1
https://github.com/the-control-group/voyager
1
https://github.com/chriskacerguis/codeigniter-restserver
1
https://github.com/simplysites/CodeIgniter
1
https://github.com/Webklex/php-imap
1
https://github.com/himiklab/yii2-jqgrid-widget
1
https://github.com/Codeception/Codeception
1
https://github.com/TYPO3-CMS/core
1
https://github.com/Chocapikk/CVE-2024-31819
1
https://github.com/thephpleague/flysystem
1
https://github.com/DBRisinajumi/d2files
1
https://github.com/xpressengine/xpressengine
1
https://github.com/zendframework/zend-json
1
https://github.com/getk2/k2
1
https://github.com/barrelstrength/craft-sprout-forms
1
https://github.com/LimeSurvey/LimeSurvey
1
https://github.com/melisplatform/melis-cms
1
https://github.com/hieuminhnv/Zenario-CMS-9.0-last-version
1
https://github.com/sabberworm/PHP-CSS-Parser
1
https://github.com/impresspages/ImpressPages
1
https://github.com/laravel/framework
1
https://github.com/symfony/serializer
1
https://github.com/YesWiki/yeswiki
1
https://github.com/simogeo/Filemanager
1
https://github.com/YOURLS/YOURLS
1
https://github.com/cachethq/cachet
1
https://github.com/ibexa/solr
1
https://github.com/azuracast/azuracast
1
https://github.com/gongfuxiang/shopxo
1
https://github.com/catfan/Medoo
1
https://github.com/spaceraccoon/CVE-2020-10665
1
https://github.com/auth0/symfony
1
https://github.com/PrestaShopCorp/ps_checkout
1
https://github.com/Rudloff/rtmpdump-bin
1