Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Packagist
Package ecosystem Packagist. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
Totals
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 82 | 82 | 33 |
Monthly trend
▁▃▅▂█▆▄
2026-04 1 · 2026-05 7 · 2026-06 15 · 2026-07 2 · 2026-08 28 · 2026-09 18 · 2026-10 11
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-31843 | 10.0 | 66.3 | — | goodoneuz/pay-uz Unauthenticated PHP File Overwrite via /payment/api/editable/update Le… |
| CVE-2026-43871 | 8.7 | 62.6 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt… |
| CVE-2026-78416 | 8.7 | 62.3 | — | Authenticated RCE via `condition.config` JSON cleanse bypass |
| CVE-2026-77136 | 9.5 | 60.7 | — | Server-Side Template Injection in extension "powermail" (powermail) |
| CVE-2026-9559 | 9.9 | 59.3 | — | — |
| CVE-2026-64837 | 8.7 | 55.6 | — | ICEcoder through 8.1 OS Command Injection via lib/properties.php |
| CVE-2026-9558 | 9.9 | 54.9 | — | — |
| CVE-2026-77138 | 9.3 | 52.3 | — | Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer… |
| CVE-2026-105985 | 8.7 | 51.2 | — | Authenticated RCE via render-components Entry Type overrides |
| CVE-2026-79987 | 8.7 | 49.5 | — | Low-privilege RCE through element-search eager loading |
| CVE-2026-64836 | 8.7 | 47.4 | — | ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement |
| CVE-2026-49740 | 6.3 | 46.4 | — | TYPO3 CMS - Insecure Deserialization in Core API |
| CVE-2026-88959 | 8.7 | 42.6 | — | Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-… |
| CVE-2026-49738 | 2.1 | 42.4 | — | TYPO3 CMS - Broken Access Control in File Abstraction Layer |
| CVE-2026-64838 | 8.7 | 42.3 | — | ICEcoder through 8.1 Path Traversal via oldFileName Parameter |
| CVE-2026-77128 | 6.3 | 41.6 | — | Broken Access Control in extension "Event management and registration" (sf_event_mgt) |
| CVE-2026-79991 | 7.1 | 41.4 | — | Authenticated SQL Injection via nested eager-loading criteria |
| CVE-2026-47347 | 5.3 | 39.7 | — | TYPO3 CMS - Open Redirect in Core Utilities |
| CVE-2026-47348 | 5.1 | 38.5 | — | TYPO3 CMS - Cross-Site Scripting in Indexed Search |
| CVE-2026-49742 | 7.1 | 37.7 | — | TYPO3 CMS - Broken Access Control in Media Module |
Most-affected packages
| Package | CVEs |
|---|---|
| apache/thrift | 11 |
| craftcms/cms | 7 |
| mautic/core | 7 |
| typo3/cms-core | 6 |
| apache-solr-for-typo3/solr | 5 |
| in2code/femanager | 4 |
| sylius/sylius | 4 |
| typo3/cms-backend | 4 |
| typo3/cms-form | 4 |
| icecoder/icecoder | 3 |
| derhansen/sf_event_mgt | 2 |
| jweiland/events2 | 2 |
| syssy/syssy-typo3-extension | 2 |
| typo3/html-sanitizer | 2 |
| anchorcms/anchor-cms | 1 |