CVE Tools

Packagist

5,111 CVEs tracked since 2006. Since Sep 2021, 10 of them reached CISA KEV.

Packagist CVEs per month

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Packagist CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-09470
2021-10320
2021-11460
2021-12630
2022-01880
2022-02861
2022-031100
2022-04530
2022-05340
2022-06600
2022-07350
2022-08450
2022-09510
2022-10280
2022-11800
2022-12540
2023-01650
2023-02580
2023-03null or fewer
2023-04910
2023-05510
2023-06560
2023-07400
2023-08450
2023-09510
2023-10550
2023-11670
2023-12430
2024-01360
2024-02640
2024-03470
2024-04420
2024-053230
2024-061651
2024-07350
2024-08490
2024-09360
2024-10720
2024-11740
2024-12421
2025-01591
2025-02600
2025-03620
2025-04592
2025-05421
2025-06391
2025-07251
2025-08390
2025-09281
2025-10640
2025-11390
2025-12640
2026-01580
2026-02960
2026-03880
2026-04570
2026-05430
2026-06180
2026-07240
2026-08410
2026-09110

Products

The products that kept showing up in Packagist's monthly top three, with their CVEs summed over those months.

  1. Magento/community-edition13310 months
  2. Moodle/moodle12813 months
  3. Magento/project-community-edition1008 months
  4. Typo3/cms804 months
  5. Thorsten/phpmyfaq768 months
  6. Craftcms/cms636 months
  7. Typo3/cms-core638 months
  8. Pimcore/pimcore516 months
  9. Microweber/microweber505 months
  10. Silverstripe/framework501 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Packagist.

  1. GHSA-jr78-w6w5-m8f8Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks—
  2. GHSA-9rcc-pmj8-ffhrSemantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)—
  3. GHSA-2xmm-m4wv-3fjhOctober CMS: Incomplete Scheme Validation in Image Resizer—
  4. CVE-2023-50462An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin....5.3
  5. CVE-2023-50459An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to e...5.4
  6. CVE-2023-50461An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitra...8.8
  7. CVE-2023-45023The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.4.2
  8. GHSA-8rr7-cvq3-gmfhleague/commonmark: Denial of service via distinctly-named attributes in the Attributes extension—
  9. GHSA-jjv6-8j6v-6j52league/commonmark: Denial of service in the SmartPunct and Attributes extensions—
  10. GHSA-f8fg-pg57-v4j8league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed—
  11. GHSA-j8pm-gj4c-rq4xleague/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters—
  12. GHSA-7w8c-qgxg-m7jxLibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates—
  13. GHSA-pg62-f8g4-4wqhphpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold—
  14. GHSA-mf8r-wm2w-f8c5phpMyFAQ public FAQ APIs expose inactive FAQ content—
  15. GHSA-88g4-74f3-63x9phpMyFAQ has Potential Authenticated Path Traversal in PDF Export—

The record

Peak rank
#4 in Jun 2015
Busiest month shown
May 2024, 323 CVEs
Months with a KEV entry
9 since Sep 2021
Monthly snapshots
186 since 2006
Packagist's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store