Packagist
5,111 CVEs tracked since 2006. Since Sep 2021, 10 of them reached CISA KEV.
Packagist CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-09 | 47 | 0 |
| 2021-10 | 32 | 0 |
| 2021-11 | 46 | 0 |
| 2021-12 | 63 | 0 |
| 2022-01 | 88 | 0 |
| 2022-02 | 86 | 1 |
| 2022-03 | 110 | 0 |
| 2022-04 | 53 | 0 |
| 2022-05 | 34 | 0 |
| 2022-06 | 60 | 0 |
| 2022-07 | 35 | 0 |
| 2022-08 | 45 | 0 |
| 2022-09 | 51 | 0 |
| 2022-10 | 28 | 0 |
| 2022-11 | 80 | 0 |
| 2022-12 | 54 | 0 |
| 2023-01 | 65 | 0 |
| 2023-02 | 58 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 91 | 0 |
| 2023-05 | 51 | 0 |
| 2023-06 | 56 | 0 |
| 2023-07 | 40 | 0 |
| 2023-08 | 45 | 0 |
| 2023-09 | 51 | 0 |
| 2023-10 | 55 | 0 |
| 2023-11 | 67 | 0 |
| 2023-12 | 43 | 0 |
| 2024-01 | 36 | 0 |
| 2024-02 | 64 | 0 |
| 2024-03 | 47 | 0 |
| 2024-04 | 42 | 0 |
| 2024-05 | 323 | 0 |
| 2024-06 | 165 | 1 |
| 2024-07 | 35 | 0 |
| 2024-08 | 49 | 0 |
| 2024-09 | 36 | 0 |
| 2024-10 | 72 | 0 |
| 2024-11 | 74 | 0 |
| 2024-12 | 42 | 1 |
| 2025-01 | 59 | 1 |
| 2025-02 | 60 | 0 |
| 2025-03 | 62 | 0 |
| 2025-04 | 59 | 2 |
| 2025-05 | 42 | 1 |
| 2025-06 | 39 | 1 |
| 2025-07 | 25 | 1 |
| 2025-08 | 39 | 0 |
| 2025-09 | 28 | 1 |
| 2025-10 | 64 | 0 |
| 2025-11 | 39 | 0 |
| 2025-12 | 64 | 0 |
| 2026-01 | 58 | 0 |
| 2026-02 | 96 | 0 |
| 2026-03 | 88 | 0 |
| 2026-04 | 57 | 0 |
| 2026-05 | 43 | 0 |
| 2026-06 | 18 | 0 |
| 2026-07 | 24 | 0 |
| 2026-08 | 41 | 0 |
| 2026-09 | 11 | 0 |
Products
The products that kept showing up in Packagist's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Packagist.
- GHSA-jr78-w6w5-m8f8Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks—
- GHSA-9rcc-pmj8-ffhrSemantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)—
- GHSA-2xmm-m4wv-3fjhOctober CMS: Incomplete Scheme Validation in Image Resizer—
- CVE-2023-50462An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin....5.3
- CVE-2023-50459An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to e...5.4
- CVE-2023-50461An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitra...8.8
- CVE-2023-45023The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.4.2
- GHSA-8rr7-cvq3-gmfhleague/commonmark: Denial of service via distinctly-named attributes in the Attributes extension—
- GHSA-jjv6-8j6v-6j52league/commonmark: Denial of service in the SmartPunct and Attributes extensions—
- GHSA-f8fg-pg57-v4j8league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed—
- GHSA-j8pm-gj4c-rq4xleague/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters—
- GHSA-7w8c-qgxg-m7jxLibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates—
- GHSA-pg62-f8g4-4wqhphpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold—
- GHSA-mf8r-wm2w-f8c5phpMyFAQ public FAQ APIs expose inactive FAQ content—
- GHSA-88g4-74f3-63x9phpMyFAQ has Potential Authenticated Path Traversal in PDF Export—
The record
- Peak rank
- #4 in Jun 2015
- Busiest month shown
- May 2024, 323 CVEs
- Months with a KEV entry
- 9 since Sep 2021
- Monthly snapshots
- 186 since 2006