Package ecosystem
Packagist package vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 4,495 vulnerabilities in Packagist packages: 16 in the last 7 days and 479 in the last 90 days, 80 of them critical and 10 exploited in the wild. The most recent, CVE-2026-61825, was published on 24 September 2026. 48 packages have a page of their own.
- Last 7 days
- 16
- Last 90 days
- 479
- Critical, all time
- 80
- Exploited in the wild
- 10
About Packagist
The main repository for PHP packages using Composer.
Packagist packages
- getgrav/grav (Packagist)63
- wwbn/avideo (Packagist)58
- concrete5/concrete5 (Packagist)46
- snipe/snipe-it (Packagist)39
- thorsten/phpmyfaq (Packagist)34
- phpmyfaq/phpmyfaq (Packagist)33
- craftcms/cms (Packagist)27
- mantisbt/mantisbt (Packagist)26
- kimai/kimai (Packagist)22
- froxlor/froxlor (Packagist)18
- yeswiki/yeswiki (Packagist)15
- twig/twig (Packagist)14
- shopper/framework (Packagist)13
- winter/wn-backend-module (Packagist)12
- facturascripts/facturascripts (Packagist)11
- guzzlehttp/guzzle (Packagist)11
- league/commonmark (Packagist)11
- admidio/admidio (Packagist)10
- librenms/librenms (Packagist)10
- Composer (Packagist)9
- mediawiki/semantic-media-wiki (Packagist)9
- pimcore/pimcore (Packagist)8
- ci4-cms-erp/ci4ms (Packagist)7
- openmage/magento-lts (Packagist)7
- paymenter/paymenter (Packagist)7
- phanan/koel (Packagist)7
- redaxo/source (Packagist)7
- alextselegidis/easyappointments (Packagist)6
- dompdf/dompdf (Packagist)6
- nukeviet/nukeviet (Packagist)6
- pheditor/pheditor (Packagist)6
- codeigniter4/framework (Packagist)5
- flightphp/core (Packagist)5
- krayin/laravel-crm (Packagist)5
- twbs/bootstrap (Packagist)5
- code16/sharp (Packagist)4
- cotonti/cotonti (Packagist)4
- dolibarr/dolibarr (Packagist)4
- guzzlehttp/psr7 (Packagist)4
- pontedilana/php-weasyprint (Packagist)4
- pterodactyl/panel (Packagist)4
- starcitizenwiki/embedvideo (Packagist)4
- studio-42/elfinder (Packagist)4
- ckeditor/ckeditor (Packagist)3
- composer/composer (Packagist)3
- phalcon/cphalcon (Packagist)3
- torrentpier/torrentpier (Packagist)3
- typo3/cms-form (Packagist)3
Latest Packagist package vulnerabilities
- CVE-2026-61825: code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before…highCVSS 8.7EPSS 0.2%
- CVE-2026-61823: code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before…highCVSS 7.3EPSS 0.2%
- CVE-2026-57440: The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for…highCVSS 7.5EPSS 0.3%
- CVE-2026-63498: Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET…highCVSS 8.7EPSS 0.2%
- CVE-2026-63493: Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with…highCVSS 4EPSS 0.3%
- CVE-2026-62368: Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can…highCVSS 8.1EPSS 0.3%
- CVE-2026-56738: phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL…highCVSS 4EPSS 0.3%
- CVE-2026-47132: phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection…mediumCVSS 5.4EPSS 0.3%
- CVE-2026-56737: phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its…highCVSS 8.1EPSS 0.4%
- CVE-2026-56736: phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to…highCVSS 8.2EPSS 0.2%
- CVE-2026-88974: WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in…mediumCVSS 5.4EPSS 0.3%
- CVE-2026-73858: Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted…mediumCVSS 5.3EPSS 0.4%
- CVE-2026-63002: REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts…mediumCVSS 4.8EPSS 0.2%
- CVE-2026-63001: REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in…mediumCVSS 4.8EPSS 0.2%
- CVE-2026-63000: REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in…mediumCVSS 6.4EPSS 0.1%
- CVE-2026-62998: REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in…mediumCVSS 4.3EPSS 0.3%
- CVE-2026-71537: Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7…mediumCVSS 6.5EPSS 0.3%
- CVE-2026-77616: Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's…mediumCVSS 6.1EPSS 0.3%
- CVE-2026-77610: Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's…mediumCVSS 6.1EPSS 0.3%
- CVE-2026-77609: Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's…mediumCVSS 6.1EPSS 0.3%
- CVE-2026-77608: Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's…mediumCVSS 6.1EPSS 0.3%
- CVE-2026-77607: Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's…mediumCVSS 6.1EPSS 0.3%
- CVE-2026-77606: Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's…mediumCVSS 6.1EPSS 0.3%
- Semantic MediaWiki missing authorization in smwtask API modulehighCVSS 7.3
- Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance taskslowCVSS 3.1
Most severe Packagist package vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-9082: Drupal Drupal core SQL injection in database abstraction APIcriticalexploited in the wildCVSS 9.8EPSS 15.7%
- CVE-2016-10033: Remote code execution in PHPMailercriticalexploited in the wildCVSS 3.1EPSS 99.7%
- CVE-2018-7602: Drupal Core Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 3.1EPSS 99.2%
- CVE-2021-21311: SSRF in adminercriticalexploited in the wildCVSS 3.1EPSS 98.5%
- CVE-2025-54068: Livewire is vulnerable to remote command execution during component property update hydrationcriticalexploited in the wildCVSS 3.1EPSS 97.1%
- CVE-2024-58136: yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Keycriticalexploited in the wildCVSS 3.1EPSS 87.8%
- CVE-2020-36193: Directory Traversal in Archive_Tarcriticalexploited in the wildCVSS 3.1EPSS 70.6%
- CVE-2020-13671: Drupal core Unrestricted Upload of File with Dangerous Typecriticalexploited in the wildCVSS 3.1EPSS 35.4%
- CVE-2018-7600: Drupal Core Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 3EPSS 100.0%
- CVE-2019-6340: Drupal Core Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 3EPSS 92.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 14 | 1 | |
| 6 Jul 2026 | 51 | 1 | |
| 13 Jul 2026 | 81 | 9 | |
| 20 Jul 2026 | 22 | 1 | |
| 27 Jul 2026 | 33 | 4 | |
| 3 Aug 2026 | 23 | 1 | |
| 10 Aug 2026 | 20 | 1 | |
| 17 Aug 2026 | 46 | 3 | |
| 24 Aug 2026 | 53 | 0 | |
| 31 Aug 2026 | 36 | 3 | |
| 7 Sep 2026 | 30 | 1 | |
| 14 Sep 2026 | 54 | 2 | |
| 21 Sep 2026 | 16 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/packagist.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Packagist package vulnerabilities", https://junglewise.ai/threats/vendors/packagist, 26 September 2026.