boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Packagist

Package ecosystem Packagist. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDPackages affected
828233

Monthly trend

▁▃▅▂█▆▄

2026-04 1 · 2026-05 7 · 2026-06 15 · 2026-07 2 · 2026-08 28 · 2026-09 18 · 2026-10 11

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-3184310.066.3—goodoneuz/pay-uz Unauthenticated PHP File Overwrite via /payment/api/editable/update Le…
CVE-2026-438718.762.6—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt…
CVE-2026-784168.762.3—Authenticated RCE via `condition.config` JSON cleanse bypass
CVE-2026-771369.560.7—Server-Side Template Injection in extension "powermail" (powermail)
CVE-2026-95599.959.3——
CVE-2026-648378.755.6—ICEcoder through 8.1 OS Command Injection via lib/properties.php
CVE-2026-95589.954.9——
CVE-2026-771389.352.3—Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer…
CVE-2026-1059858.751.2—Authenticated RCE via render-components Entry Type overrides
CVE-2026-799878.749.5—Low-privilege RCE through element-search eager loading
CVE-2026-648368.747.4—ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement
CVE-2026-497406.346.4—TYPO3 CMS - Insecure Deserialization in Core API
CVE-2026-889598.742.6—Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-…
CVE-2026-497382.142.4—TYPO3 CMS - Broken Access Control in File Abstraction Layer
CVE-2026-648388.742.3—ICEcoder through 8.1 Path Traversal via oldFileName Parameter
CVE-2026-771286.341.6—Broken Access Control in extension "Event management and registration" (sf_event_mgt)
CVE-2026-799917.141.4—Authenticated SQL Injection via nested eager-loading criteria
CVE-2026-473475.339.7—TYPO3 CMS - Open Redirect in Core Utilities
CVE-2026-473485.138.5—TYPO3 CMS - Cross-Site Scripting in Indexed Search
CVE-2026-497427.137.7—TYPO3 CMS - Broken Access Control in Media Module

Most-affected packages

Packages with the most advisories
PackageCVEs
apache/thrift11
craftcms/cms7
mautic/core7
typo3/cms-core6
apache-solr-for-typo3/solr5
in2code/femanager4
sylius/sylius4
typo3/cms-backend4
typo3/cms-form4
icecoder/icecoder3
derhansen/sf_event_mgt2
jweiland/events22
syssy/syssy-typo3-extension2
typo3/html-sanitizer2
anchorcms/anchor-cms1