Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Package ecosystem Packagist. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 26 | 26 | 11 |
▁▄█▂▁
2026-04 1 · 2026-05 7 · 2026-06 15 · 2026-07 2 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-31843 | 10.0 | 68.2 | — | goodoneuz/pay-uz Unauthenticated PHP File Overwrite via /payment/api/editable/update Le… |
| CVE-2026-43871 | 8.7 | 62.3 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt… |
| CVE-2026-9559 | 9.9 | 45.3 | — | — |
| CVE-2026-9558 | 9.9 | 44.7 | — | — |
| CVE-2026-47345 | 5.1 | 29.8 | — | TYPO3 HTML Sanitizer allows Cross-Site Scripting |
| CVE-2026-49738 | 2.1 | 28.8 | — | TYPO3 CMS - Broken Access Control in File Abstraction Layer |
| CVE-2026-49742 | 7.1 | 24.1 | — | TYPO3 CMS - Broken Access Control in Media Module |
| CVE-2026-47347 | 5.3 | 22.0 | — | TYPO3 CMS - Open Redirect in Core Utilities |
| CVE-2026-47344 | 2.1 | 20.8 | — | TYPO3 HTML Sanitizer allows Cross-Site Scripting |
| CVE-2026-47348 | 5.1 | 19.2 | — | TYPO3 CMS - Cross-Site Scripting in Indexed Search |
| CVE-2026-47346 | 7.6 | 17.0 | — | TYPO3 CMS - Broken Access Control in Form Framework |
| CVE-2026-49741 | 8.7 | 15.9 | — | TYPO3 CMS - Privilege Escalation & SQL Injection in Form Framework |
| CVE-2026-11607 | 7.6 | 15.1 | — | TYPO3 CMS - Broken Access Control in Form Framework |
| CVE-2026-47343 | 7.2 | 15.1 | — | TYPO3 CMS - Destructive Actions on File Mount Folders |
| CVE-2026-47349 | 5.3 | 15.1 | — | TYPO3 CMS - Broken Access Control in Recycler |
| CVE-2026-47350 | 5.3 | 15.1 | — | TYPO3 CMS - Broken Access Control in DataHandler |
| CVE-2026-47351 | 5.3 | 15.1 | — | TYPO3 CMS - Broken Access Control in Clipboard |
| CVE-2026-47352 | 5.3 | 15.1 | — | TYPO3 CMS - Broken Access Control in Backend API |
| CVE-2026-4776 | 7.1 | 13.3 | — | — |
| CVE-2026-49740 | 6.3 | 12.2 | — | TYPO3 CMS - Insecure Deserialization in Core API |
| Package | CVEs |
|---|---|
| mautic/core | 7 |
| typo3/cms-core | 6 |
| typo3/cms-form | 4 |
| typo3/cms-backend | 3 |
| typo3/html-sanitizer | 2 |
| apache/thrift | 1 |
| goodoneuz/pay-uz | 1 |
| typo3/cms-filelist | 1 |
| typo3/cms-indexed-search | 1 |
| typo3/cms-install | 1 |
| typo3/cms-recycler | 1 |