packagist
471,937 packages · packagist.org
Security Advisories in packagist
High
almost 4 years ago
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
packagist
showdoc/showdoc
Moderate
almost 4 years ago
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
packagist
showdoc/showdoc
Low
almost 4 years ago
bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
packagist
ssddanbrown/bookstack
Critical
almost 4 years ago
OS Command Injection Vulnerability and Potential Zip Slip Vulnerability in baserCMS
packagist
baserproject/basercms
High
almost 4 years ago
Potential Zip Slip Vulnerability in baserCMS
packagist
baserproject/basercms
Moderate
almost 4 years ago
XSS in richtext custom tag attributes in ezsystems/ezplatform-richtext
packagist
ezsystems/ezplatform-admin-ui
Moderate
almost 4 years ago
XSS in richtext custom tag attributes in ezsystems/ezplatform-richtext
packagist
ezsystems/ezplatform-richtext
Moderate
almost 4 years ago
bookstack is vulnerable to Improper Access Control
packagist
ssddanbrown/bookstack
Moderate
almost 4 years ago
EC-CUBE Improper access control in Management screen
packagist
ec-cube/ec-cube
Moderate
almost 4 years ago
Cookie persistence after password changes in symfony/security-bundle
packagist
symfony/security-bundle
Critical
almost 4 years ago
Webcache Poisoning in shopware/platform and shopware/core
packagist
shopware/platform, shopware/core
Moderate
almost 4 years ago
Exposure of sensitive information in concrete5/core
packagist
concrete5/core
Critical
almost 4 years ago
Moodle vulnerable to RCE via unsafe deserialization
packagist
moodle/moodle
Moderate
almost 4 years ago
The disqualify lead action may be executed without CSRF token check
packagist
oro/crm
Moderate
almost 4 years ago
Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys
packagist
pterodactyl/panel
High
almost 4 years ago
HTML comments vulnerability allowing to execute JavaScript code
packagist, npm
ckeditor/ckeditor, ckeditor4
Moderate
almost 4 years ago
Cross-site scripting (XSS) from image block content in the site frontend
packagist
getkirby/cms
Moderate
almost 4 years ago
Cross-site scripting (XSS) from writer field content in the site frontend
packagist
getkirby/cms
Moderate
almost 4 years ago
twill is vulnerable to Cross-Site Request Forgery (CSRF)
packagist
area17/twill
Moderate
almost 4 years ago
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
packagist
snipe/snipe-it
Moderate
almost 4 years ago
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
packagist
grumpydictator/firefly-iii
High
almost 4 years ago
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
packagist
ssddanbrown/bookstack
Moderate
almost 4 years ago
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
packagist
showdoc/showdoc
Moderate
almost 4 years ago
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
packagist
showdoc/showdoc
Moderate
almost 4 years ago
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
packagist
showdoc/showdoc
Moderate
almost 4 years ago
Cross-site Scripting in pegasus/google-for-jobs
packagist
pegasus/google-for-jobs
High
almost 4 years ago
Unrestricted access to predictable file paths in hov/jobfair
packagist
hov/jobfair
High
almost 4 years ago
Insecure Inherited Permissions in neoan3-apps/template
packagist
neoan3-apps/template
Moderate
almost 4 years ago
Cross-site scripting vulnerability in TinyMCE plugins
pypi, nuget, packagist, npm
django-tinymce, TinyMCE, tinymce/tinymce, tinymce
Moderate
about 4 years ago
Cross-Site Request Forgery in firefly-iii
packagist
grumpydictator/firefly-iii
Low
about 4 years ago
Cross-Site Request Forgery in firefly-iii
packagist
grumpydictator/firefly-iii
Moderate
about 4 years ago
Authenticated Stored XSS in shopware/shopware
packagist
shopware/shopware
Low
about 4 years ago
pterodactyl/panel CSRF allowing an external page to trigger a user logout event
packagist
pterodactyl/panel
Moderate
about 4 years ago
Cross-site scripting vulnerability in TinyMCE
packagist, nuget, npm
tinymce/tinymce, TinyMCE, tinymce
Moderate
about 4 years ago
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in sulu/sulu
packagist
sulu/sulu
Moderate
about 4 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Moodle
packagist
moodle/moodle
Moderate
about 4 years ago
SilverStripe GraphQL Server permission checker not inherited by query subclass.
packagist
silverstripe/graphql
Moderate
about 4 years ago
Cross-site Scripting in SilverStripe Framework
packagist
silverstripe/admin
High
about 4 years ago
Server-Side Request Forgery vulnerability in concrete5
packagist
concrete5/concrete5
Moderate
about 4 years ago
Improper Certificate Validation in Heartland & Global Payments PHP SDK
packagist
globalpayments/php-sdk
High
about 4 years ago
Drupal core Unrestricted Upload of File with Dangerous Type
packagist
drupal/core
Moderate
about 4 years ago
Stored XSS with custom URLs in PrestaShop module ps_linklist
packagist
prestashop/ps_linklist
High
about 4 years ago
Sylius PayPal Plugin allows unauthorized access to Credit card form, exposing payer name and not requiring 3DS
packagist
sylius/paypal-plugin
High
about 4 years ago
Deleted Admin Can Sign In to Admin Interface
packagist
october/system, october/october
High
about 4 years ago
Improper escaping of command arguments on Windows leading to command injection
packagist
composer/composer
High
about 4 years ago
Pterodactyl Panel vulnerable to authentication bypass due to improper user-provided security token verification
packagist
pterodactyl/panel
Moderate
about 4 years ago
Cross-site scripting in demos/demo.mysqli.php in getID3
packagist
james-heinrich/getid3
Moderate
about 4 years ago
Cross-site scripting in application/controllers/dropbox.php in JustWriting
packagist
hjue/justwriting
Critical
about 4 years ago
Directory Traversal in typo3/phar-stream-wrapper
packagist
typo3/phar-stream-wrapper
Critical
about 4 years ago
Improper Access Control in Webauthn Framework
packagist
web-auth/webauthn-framework
Moderate
about 4 years ago
Reliance on Cookies without Validation and Integrity Checking in getgrav/grav
packagist
getgrav/grav
Moderate
about 4 years ago
Cross-Site Request Forgery in firefly-iii
packagist
grumpydictator/firefly-iii
Moderate
about 4 years ago
File reference keys leads to incorrect hashes on HMAC algorithms
packagist
lcobucci/jwt
High
about 4 years ago
User can obtain JWT token even if account is disabled
packagist
ezsystems/ezplatform-rest
Moderate
about 4 years ago
Observable Response Discrepancy in Lost Password Service
packagist
pimcore/pimcore
High
about 4 years ago
Any storage file can be downloaded from p.sh if full server path is known
packagist
ezsystems/ezplatform
Filter by Severity
Filter by Package
moodle/moodle
425
magento/community-edition
325
typo3/cms
163
pimcore/pimcore
120
dolibarr/dolibarr
117
phpmyadmin/phpmyadmin
107
typo3/cms-core
106
microweber/microweber
103
drupal/core
99
silverstripe/framework
90
librenms/librenms
86
magento/project-community-edition
83
thorsten/phpmyfaq
74
drupal/drupal
71
concrete5/concrete5
67
shopware/platform
63
symfony/symfony
57
craftcms/cms
53
shopware/core
51
mautic/core
48
baserproject/basercms
47
nilsteampassnet/teampass
42
mantisbt/mantisbt
41
showdoc/showdoc
41
intelliants/subrion
40
froxlor/froxlor
40
snipe/snipe-it
38
zendframework/zendframework1
32
shopware/shopware
31
getgrav/grav
30
contao/core-bundle
29
mediawiki/core
28
prestashop/prestashop
27
centreon/centreon
27
pocketmine/pocketmine-mp
25
getkirby/cms
24
magento/core
24
simplesamlphp/simplesamlphp
23
remdex/livehelperchat
23
laravel/framework
23
grumpydictator/firefly-iii
23
phpoffice/phpspreadsheet
22
tribalsystems/zenario
22
zendframework/zendframework
22
funadmin/funadmin
20
cockpit-hq/cockpit
20
typo3/cms-backend
20
topthink/framework
19
contao/contao
19
forkcms/forkcms
18
genix/cms
18
opencart/opencart
17
cakephp/cakephp
17
ezsystems/ezpublish-kernel
17
yetiforce/yetiforce-crm
17
openmage/magento-lts
17
francoisjacquet/rosariosis
17
phpbb/phpbb
16
smarty/smarty
15
pimcore/admin-ui-classic-bundle
15
october/system
15
bolt/bolt
15
ec-cube/ec-cube
15
silverstripe/cms
15
dompdf/dompdf
14
phpmailer/phpmailer
14
admidio/admidio
14
codeigniter4/framework
14
modx/revolution
14
yeswiki/yeswiki
14
feehi/cms
14
symfony/security
13
phpmyfaq/phpmyfaq
13
elefant/cms
13
studio-42/elfinder
13
impresscms/impresscms
13
lavalite/cms
13
alextselegidis/easyappointments
13
bagisto/bagisto
12
wwbn/avideo
12
sylius/sylius
12
wallabag/wallabag
12
TinyMCE
11
symfony/security-http
11
tinymce
11
leantime/leantime
11
nukeviet/nukeviet
11
tinymce/tinymce
11
sulu/sulu
11
pagekit/pagekit
11
yiisoft/yii2
11
feehi/feehicms
11
ezsystems/ezplatform-kernel
11
ezsystems/ezpublish-legacy
10
statamic/cms
10
october/october
10
ezsystems/ezplatform-admin-ui
10
spatie/browsershot
10
symfony/http-foundation
10
ssddanbrown/bookstack
10
twig/twig
9
croogo/croogo
9
concrete5/core
9
in2code/femanager
9
pimcore/customer-management-framework-bundle
9
starcitizentools/citizen-skin
9
kevinpapst/kimai2
9
billz/raspap-webgui
9
in2code/powermail
9
pterodactyl/panel
9
contao/core
9
tecnickcom/tcpdf
8
silverstripe/admin
8
gilacms/gila
8
directmailteam/direct-mail
8
codiad/codiad
8
flarum/core
8
silverstripe/graphql
8
facturascripts/facturascripts
8
october/cms
8
joomla/joomla-cms
8
composer/composer
8
passbolt/passbolt_api
7
redaxo/source
7
unopim/unopim
7
symfony/http-kernel
7
backdrop/backdrop
7
october/backend
7
wpglobus/wpglobus
7
vrana/adminer
7
simplesamlphp/saml2
7
shopxo/shopxo
7
yiisoft/yii2-dev
7
gleez/cms
6
yourls/yourls
6
icecoder/icecoder
6
typo3/cms-install
6
ibexa/admin-ui
6
dweeves/magmi
6
adodb/adodb-php
6
oro/platform
6
phpseclib/phpseclib
6
nystudio107/craft-seomatic
6
pear/archive_tar
6
guzzlehttp/guzzle
6
api-platform/core
6
zoujingli/thinkadmin
6
limesurvey/limesurvey
5
bottelet/flarepoint
5
juzaweb/cms
5
neos/neos
5
elgg/elgg
5
processwire/processwire
5
woocommerce/woocommerce
5
illuminate/database
5
ibexa/core
5
tcg/voyager
5
typo3/flow
5
phpxmlrpc/phpxmlrpc
5
phpservermon/phpservermon
5
getformwork/formwork
5
mautic/core-lib
5
gugoan/economizzer
5
anchorcms/anchor-cms
5
neos/flow
5
kimai/kimai
5
cachethq/cachet
5
symfony/security-core
5
thinkcmf/thinkcmf
5
yiisoft/yii
4
reportico-web/reportico
4
enshrined/svg-sanitize
4
bytefury/crater
4
shopware/storefront
4
bref/bref
4
automad/automad
4
friendsofsymfony/user-bundle
4
drupal/core-recommended
4
flarum/framework
4
silverstripe/assets
4
wp-premium/gravityforms
4
idno/known
4
froala/wysiwyg-editor
4
drupal/ai
4
ibexa/fieldtype-richtext
4
codeigniter/framework
4
notrinos/notrinos-erp
4
typo3/html-sanitizer
4
elmsln/haxcms
4
appwrite/server-ce
4
typo3/cms-form
4
typo3/cms-frontend
4
codeigniter4/shield
4
pyrocms/pyrocms
4
ezsystems/ezplatform
4
league/commonmark
4
privatebin/privatebin
4
auth0/wordpress
4
moonshine/moonshine
4
oro/commerce
4
Filter by Repository
https://github.com/moodle/moodle
250
https://github.com/pimcore/pimcore
116
https://github.com/TYPO3/typo3
94
https://github.com/microweber/microweber
90
https://github.com/librenms/librenms
77
https://github.com/thorsten/phpmyfaq
69
https://github.com/silverstripe/silverstripe-framework
68
https://github.com/symfony/symfony
64
https://github.com/Dolibarr/dolibarr
60
https://github.com/mautic/mautic
46
https://github.com/phpmyadmin/phpmyadmin
45
https://github.com/concretecms/concretecms
44
https://github.com/shopware/platform
43
https://github.com/craftcms/cms
41
https://github.com/shopware/shopware
40
https://github.com/star7th/showdoc
39
https://github.com/mantisbt/mantisbt
38
https://github.com/magento/magento2
38
https://github.com/octobercms/october
36
https://github.com/snipe/snipe-it
30
https://github.com/contao/contao
30
https://github.com/baserproject/basercms
26
https://github.com/froxlor/froxlor
26
https://github.com/pmmp/PocketMine-MP
25
https://github.com/getgrav/grav
24
https://github.com/nilsteampassnet/TeamPass
23
https://github.com/firefly-iii/firefly-iii
23
https://github.com/PrestaShop/PrestaShop
23
https://github.com/TYPO3/TYPO3.CMS
23
https://github.com/livehelperchat/livehelperchat
23
https://github.com/PHPOffice/PhpSpreadsheet
22
https://github.com/getkirby/kirby
22
https://github.com/laravel/framework
21
https://github.com/simplesamlphp/simplesamlphp
20
https://github.com/funadmin/funadmin
20
https://github.com/intelliants/subrion
19
https://github.com/nilsteampassnet/teampass
19
https://github.com/TYPO3-CMS/core
19
https://github.com/liufee/cms
17
https://github.com/OpenMage/magento-lts
17
https://github.com/forkcms/forkcms
16
https://github.com/yetiforcecompany/yetiforcecrm
16
https://github.com/drupal/core
15
https://github.com/dompdf/dompdf
15
https://github.com/centreon/centreon
15
https://github.com/thorsten/phpMyFAQ
15
https://github.com/zendframework/zendframework
15
https://github.com/PHPMailer/PHPMailer
15
https://github.com/cockpit-hq/cockpit
14
https://github.com/pimcore/admin-ui-classic-bundle
14
https://github.com/yiisoft/yii2
12
https://github.com/centreon/centreon-archived
12
https://github.com/modxcms/revolution
12
https://github.com/smarty-php/smarty
12
https://github.com/YesWiki/yeswiki
12
https://sourceforge.net/projects/phpmyadmin.sourceforge.net
12
https://github.com/codeigniter4/CodeIgniter4
12
https://github.com/ezsystems/ezpublish-kernel
11
https://github.com/top-think/framework
11
https://github.com/Studio-42/elFinder
11
https://github.com/sulu/sulu
11
https://github.com/WWBN/AVideo
11
https://github.com/Leantime/leantime
11
https://github.com/cakephp/cakephp
11
https://github.com/tinymce/tinymce
11
https://github.com/Sylius/Sylius
11
https://github.com/dolibarr/dolibarr
11
https://github.com/bolt/bolt
10
https://github.com/semplon/GeniXCMS
10
https://github.com/wallabag/wallabag
10
https://github.com/opencart/opencart
10
https://github.com/neorazorx/facturascripts
9
https://github.com/kevinpapst/kimai2
9
https://github.com/StarCitizenTools/mediawiki-skins-Citizen
9
https://github.com/statamic/cms
9
https://github.com/pterodactyl/panel
9
https://github.com/bagisto/bagisto
9
https://github.com/alextselegidis/easyappointments
9
https://github.com/spatie/browsershot
9
https://github.com/LavaLite/cms
9
https://github.com/twigphp/Twig
8
https://github.com/GilaCMS/gila
8
https://github.com/Froxlor/Froxlor
8
https://github.com/tecnickcom/TCPDF
8
https://github.com/pimcore/customer-data-framework
8
https://github.com/admidio/admidio
8
https://github.com/TribalSystems/Zenario
8
https://github.com/francoisjacquet/rosariosis
8
https://github.com/croogo/croogo
8
https://github.com/RaspAP/raspap-webgui
8
https://github.com/flarum/framework
8
https://github.com/ezsystems/ezplatform-admin-ui
8
https://github.com/composer/composer
7
https://github.com/wintercms/winter
7
https://github.com/d4wner/Vulnerabilities-Report
7
https://github.com/ezsystems/ezplatform-kernel
7
https://github.com/unopim/unopim
7
https://github.com/passbolt/passbolt_api
7
https://github.com/Codiad/Codiad
7
https://github.com/pagekit/pagekit
7
https://github.com/phpseclib/phpseclib
6
https://github.com/guzzle/guzzle
6
https://github.com/gleez/cms
6
https://github.com/silverstripe/silverstripe-graphql
6
https://github.com/auth0/auth0-PHP
6
https://github.com/ADOdb/ADOdb
6
https://gitlab.com/francoisjacquet/rosariosis
6
https://github.com/api-platform/core
6
https://github.com/ImpressCMS/impresscms
6
https://github.com/Admidio/admidio
6
https://github.com/LimeSurvey/LimeSurvey
6
https://github.com/bookstackapp/bookstack
6
https://github.com/vrana/adminer
6
https://github.com/oroinc/orocommerce
6
https://github.com/ezsystems/ezpublish-legacy
6
https://github.com/nystudio107/craft-seomatic
6
https://github.com/dub-flow/vulnerability-research
5
https://github.com/gggeek/phpxmlrpc
5
https://github.com/Bottelet/DaybydayCRM
5
https://github.com/contao/core
5
https://github.com/in2code-de/femanager
5
https://github.com/nukeviet/nukeviet
5
https://github.com/backdrop/backdrop
5
https://github.com/thinkcmf/thinkcmf
5
https://github.com/zendframework/zf1
5
https://github.com/ibexa/core
5
https://github.com/oroinc/platform
5
https://github.com/ibexa/admin-ui
5
https://github.com/jbroadway/elefant
5
https://github.com/getformwork/formwork
5
https://github.com/shopware5/shopware
5
https://github.com/pear/Archive_Tar
5
https://github.com/reportico-web/reportico
4
https://github.com/BookStackApp/BookStack
4
https://github.com/oroinc/crm
4
https://github.com/phpservermon/phpservermon
4
https://github.com/pixelfed/pixelfed
4
https://github.com/Sylius/SyliusResourceBundle
4
https://github.com/appwrite/appwrite
4
https://github.com/fiveai/Cachet
4
https://github.com/hieuminhnv/Zenario-CMS-last-version
4
https://github.com/yourls/yourls
4
https://github.com/codeigniter4/shield
4
https://github.com/GiacoLenzo2109/MoonShine_Software_PoCs
4
https://github.com/ezsystems/ezplatform-richtext
4
https://github.com/TYPO3/html-sanitizer
4
https://github.com/Cockpit-HQ/Cockpit
4
https://github.com/zoujingli/ThinkAdmin
4
https://github.com/in2code-de/powermail
4
https://github.com/haxtheweb/issues
4
https://github.com/darylldoyle/svg-sanitizer
4
https://github.com/crater-invoice/crater
4
https://github.com/livewire/livewire
4
https://github.com/kimai/kimai
4
https://github.com/PrivateBin/PrivateBin
4
https://github.com/progprnv/CVE-Reports
4
https://github.com/froxlor/Froxlor
4
https://github.com/silverstripe/silverstripe-admin
4
https://github.com/ezsystems/ezplatform
4
https://github.com/brefphp/bref
4
https://github.com/auth0/wordpress
3
https://github.com/yiisoft/yii
3
https://github.com/liufee/feehicms
3
https://github.com/idno/known
3
https://github.com/Sylius/PayPalPlugin
3
https://github.com/thephpleague/commonmark
3
https://github.com/notrinos/notrinoserp
3
https://github.com/qcubed/qcubed
3
https://github.com/PrestaShopCorp/ps_checkout
3
https://github.com/artesaos/seotools
3
https://github.com/wikimedia/mediawiki
3
https://github.com/uvdesk/community-skeleton
3
https://github.com/TYPO3-Solr/ext-solr
3
https://github.com/PrestaShop/productcomments
3
https://github.com/ezsystems/ezplatform-http-cache
3
https://github.com/verbb/formie
3
https://github.com/verbb/comments
3
https://github.com/phpbb/phpbb
3
https://github.com/aimeos/ai-admin-graphql
3
https://github.com/simplesamlphp/saml2
3
https://github.com/flarum/core
3
https://github.com/UniSharp/laravel-filemanager
3
https://github.com/guzzle/psr7
3
https://github.com/woocommerce/woocommerce
3
https://github.com/ibexa/fieldtype-richtext
3
https://github.com/grokability/snipe-it
3
https://github.com/uasoft-indonesia/badaso
3
https://github.com/phpbb/phpbb-app
3
https://github.com/joomla/joomla-cms
3
https://github.com/FriendsOfSymfony/FOSUserBundle
3
https://github.com/quickapps/cms
3
https://github.com/opensource-workshop/connect-cms
3
https://github.com/thedevdojo/voyager
3
https://github.com/alexbsec/CVEs
3
https://github.com/belong2yourself/vulnerabilities
3
https://github.com/facade/ignition
3
https://github.com/Rudloff/alltube
3
https://github.com/redaxo/redaxo
3
https://github.com/xjzzzxx/vulFound
3