Skip to content

Package advisories

Packagist

278advisory rows225advisories91packagesRSSas of the 2026-09-07 snapshot

An advisory is the GHSA entry a Dependabot alert links to; GitHub-reviewed only. One row is one change to one package: 25 fixed-in version changed, 253 package added later.

No rate: 35,259 advisories were compared across every ecosystem together, and the analysis carries no count of how many were Packagist, so nothing here divides one number by the other.

Kind of change

253 counted rows in this one change · showing 201 to 250 · newest advisory first

One change, in full: Package added to advisory: 80 packages named as affected in packagist. The same change, 253 rows across 211 advisories. Back to packagist

Changes to GitHub-reviewed advisories naming a package in packagist. Each row gives the kind of change and the advisory it happened to. Where the same change was made to several advisories or packages at once, one row stands for all of them, says how many, and opens to every one. Then the ecosystem and package, what the advisory said beside what it says now, GitHub's severity level, and the date the advisory was published.
Package, The package the change names, or where one row stands for the same change across several packages, how many.Kind of changeAdvisory, The advisory id, or where one row stands for the same change made to several advisories, how many it stands for. An advisory id links to GitHub, and a CVE id is shown beside it where the advisory names one.What changedSeverity, GitHub's severity level for the advisory as it stands today: low, moderate, high or critical. Where one row stands for advisories at more than one level, it says how many levels, never one of them.Advisory published, The date the advisory was published. Every lag on this source is measured from it, and it is a third clock beside the CVE catalog's publication date and the date CISA added an entry to KEV. Two kinds of change also carry a date of their own: a withdrawal states its own timestamp, and a changed fix version is dated by reading back through the dated saves of the advisory file until the one where the version first reached the value it has today. A package added and a severity changed leave no commit of their own to date, so for those the date of the change is not recorded at all. That is absence, never same-day.
vrana/adminerPackage added to advisoryGHSA-m56g-3g8v-2rxwnot named as affected when the advisory was published, now names vrana/adminermoderate2021-02-11
tinymce/tinymcePackage added to advisoryGHSA-w7jx-j77m-wp65CVE-2024-21911not named as affected when the advisory was published, now names tinymce/tinymcemoderate2021-01-06
typo3/cmsPackage added to advisoryGHSA-vqqx-jw6p-q3rfCVE-2020-26227not named as affected when the advisory was published, now names typo3/cmsmoderate2020-12-21
typo3/cmsPackage added to advisoryGHSA-q9cp-mc96-m4w2CVE-2020-26229not named as affected when the advisory was published, now names typo3/cmslow2020-11-23
typo3/cmsPackage added to advisoryGHSA-954j-f27r-cj52CVE-2020-26228not named as affected when the advisory was published, now names typo3/cmshigh2020-11-23
typo3/cmsPackage added to advisoryGHSA-7733-hjv6-4h47CVE-2020-15241not named as affected when the advisory was published, now names typo3/cmsmoderate2020-10-08
typo3/cms-corePackage added to advisoryGHSA-7733-hjv6-4h47CVE-2020-15241not named as affected when the advisory was published, now names typo3/cms-coremoderate2020-10-08
contao/contaoPackage added to advisoryGHSA-f7wm-x4gw-6m23CVE-2020-25768not named as affected when the advisory was published, now names contao/contaomoderate2020-09-24
datatables/datatablesPackage added to advisoryGHSA-4mv4-gmmf-q382CVE-2015-6584not named as affected when the advisory was published, now names datatables/datatableshigh2020-08-31
typo3/cmsPackage added to advisoryGHSA-3x94-fv5h-5q2cCVE-2020-15099not named as affected when the advisory was published, now names typo3/cmshigh2020-07-29
typo3/cmsPackage added to advisoryGHSA-m5vr-3m74-jwxpCVE-2020-15098not named as affected when the advisory was published, now names typo3/cmshigh2020-07-29
maikuolan/phpmusselPackage added to advisoryGHSA-qr95-4mq5-r3fhCVE-2020-4043not named as affected when the advisory was published, now names maikuolan/phpmusselhigh2020-06-10
typo3/cmsPackage added to advisoryGHSA-pqg8-crx9-g8m4CVE-2020-11069not named as affected when the advisory was published, now names typo3/cmshigh2020-05-13
typo3/cmsPackage added to advisoryGHSA-2wj9-434x-9hvpCVE-2020-11067not named as affected when the advisory was published, now names typo3/cmshigh2020-05-13
typo3/cmsPackage added to advisoryGHSA-2rxh-h6h9-qrqcCVE-2020-11066not named as affected when the advisory was published, now names typo3/cmshigh2020-05-13
typo3/cmsPackage added to advisoryGHSA-4j77-gg36-9864CVE-2020-11065not named as affected when the advisory was published, now names typo3/cmsmoderate2020-05-13
typo3/cmsPackage added to advisoryGHSA-43gj-mj2w-wh46CVE-2020-11064not named as affected when the advisory was published, now names typo3/cmsmoderate2020-05-13
typo3/cmsPackage added to advisoryGHSA-347x-877p-hcwxCVE-2020-11063not named as affected when the advisory was published, now names typo3/cmslow2020-05-13
components/jqueryPackage added to advisoryGHSA-jpcq-cgw6-v4j6CVE-2020-11023not named as affected when the advisory was published, now names components/jquerymoderate2020-04-29
athlon1600/youtube-downloaderPackage added to advisoryGHSA-gxr4-xjj5-5px2CVE-2020-11022not named as affected when the advisory was published, now names athlon1600/youtube-downloadermoderate2020-04-29
components/jqueryPackage added to advisoryGHSA-gxr4-xjj5-5px2CVE-2020-11022not named as affected when the advisory was published, now names components/jquerymoderate2020-04-29
maximebf/debugbarPackage added to advisoryGHSA-gxr4-xjj5-5px2CVE-2020-11022not named as affected when the advisory was published, now names maximebf/debugbarmoderate2020-04-29
sylius/grid-bundlePackage added to advisoryGHSA-rc5r-697f-28x6CVE-2019-12186not named as affected when the advisory was published, now names sylius/grid-bundlemoderate2020-04-15
sylius/syliusPackage added to advisoryGHSA-rc5r-697f-28x6CVE-2019-12186not named as affected when the advisory was published, now names sylius/syliusmoderate2020-04-15
symfony/symfonyPackage added to advisoryGHSA-g4m9-5hpf-hx72CVE-2020-5275not named as affected when the advisory was published, now names symfony/symfonyhigh2020-03-30
symfony/error-handlerPackage added to advisoryGHSA-m884-279h-32v2CVE-2020-5274not named as affected when the advisory was published, now names symfony/error-handlermoderate2020-03-30
symfony/symfonyPackage added to advisoryGHSA-m884-279h-32v2CVE-2020-5274not named as affected when the advisory was published, now names symfony/symfonymoderate2020-03-30
symfony/symfonyPackage added to advisoryGHSA-mcx4-f5f5-4859CVE-2020-5255not named as affected when the advisory was published, now names symfony/symfonylow2020-03-30
typo3/cmsPackage added to advisoryGHSA-w2fr-65vp-mxw3CVE-2019-10912not named as affected when the advisory was published, now names typo3/cmshigh2020-02-12
typo3/cms-corePackage added to advisoryGHSA-w2fr-65vp-mxw3CVE-2019-10912not named as affected when the advisory was published, now names typo3/cms-corehigh2020-02-12
contao/contaoPackage added to advisoryGHSA-jc43-qrrp-98f5CVE-2019-19714not named as affected when the advisory was published, now names contao/contaomoderate2019-12-17
contao/contaoPackage added to advisoryGHSA-4mvc-qc5w-v5qrCVE-2019-19712not named as affected when the advisory was published, now names contao/contaomoderate2019-12-17
contao/contaoPackage added to advisoryGHSA-wjx8-cgrm-hh8pCVE-2019-19745not named as affected when the advisory was published, now names contao/contaohigh2019-12-17
phpoffice/phpexcelPackage added to advisoryGHSA-vvwv-h69m-wg6fCVE-2019-12331not named as affected when the advisory was published, now names phpoffice/phpexcelhigh2019-11-20
phpoffice/phpexcelPackage added to advisoryGHSA-xcrg-29h7-h4cjCVE-2018-19277not named as affected when the advisory was published, now names phpoffice/phpexcelhigh2019-11-20
magento/project-community-editionPackage added to advisoryGHSA-h7qw-mxrm-c6h2CVE-2016-6485not named as affected when the advisory was published, now names magento/project-community-editionhigh2019-11-20
silverstripe/assetsPackage added to advisoryGHSA-jvx5-rm6q-gx7pCVE-2019-12245not named as affected when the advisory was published, now names silverstripe/assetsmoderate2019-11-12
silverstripe/frameworkPackage added to advisoryGHSA-xm6j-x342-gwq9CVE-2019-16409not named as affected when the advisory was published, now names silverstripe/frameworkmoderate2019-11-12
drupal/corePackage added to advisoryGHSA-g996-q5r8-w7g2CVE-2019-10909not named as affected when the advisory was published, now names drupal/coremoderate2019-11-12
drupal/drupalPackage added to advisoryGHSA-g996-q5r8-w7g2CVE-2019-10909not named as affected when the advisory was published, now names drupal/drupalmoderate2019-11-12
magento/product-community-editionPackage added to advisoryGHSA-89ch-hqf9-rgp3CVE-2019-8121not named as affected when the advisory was published, now names magento/product-community-editionhigh2019-11-12
drupal/drupalPackage added to advisoryGHSA-v3f6-f29f-rgvpCVE-2017-6923not named as affected when the advisory was published, now names drupal/drupalmoderate2019-10-10
maximebf/debugbarPackage added to advisoryGHSA-6c3j-c64m-qhgqCVE-2019-11358not named as affected when the advisory was published, now names maximebf/debugbarmoderate2019-04-26
twbs/bootstrapPackage added to advisoryGHSA-9v3m-8fp8-mj99CVE-2019-8331not named as affected when the advisory was published, now names twbs/bootstrapmoderate2019-02-22
twbs/bootstrapPackage added to advisoryGHSA-ph58-4vrj-w6hrCVE-2018-20677not named as affected when the advisory was published, now names twbs/bootstrapmoderate2019-01-17
twbs/bootstrapPackage added to advisoryGHSA-3mgp-fx93-9xv5CVE-2018-20676not named as affected when the advisory was published, now names twbs/bootstrapmoderate2019-01-17
twbs/bootstrapPackage added to advisoryGHSA-4p24-vmcr-4gqjCVE-2016-10735not named as affected when the advisory was published, now names twbs/bootstrapmoderate2019-01-17
typo3/cmsPackage added to advisoryGHSA-g68x-vvqq-pvw3CVE-2018-17960not named as affected when the advisory was published, now names typo3/cmsmoderate2018-11-21
typo3/cms-corePackage added to advisoryGHSA-g68x-vvqq-pvw3CVE-2018-17960not named as affected when the advisory was published, now names typo3/cms-coremoderate2018-11-21
twbs/bootstrapPackage added to advisoryGHSA-7mvr-5x2g-wfc8CVE-2018-14042not named as affected when the advisory was published, now names twbs/bootstrapmoderate2018-09-13

Every change counted from this source is on this page, so an advisory with no row here had no change of that kind. No finding here is not an all clear. It means this check found nothing in the history it can see, not that nothing happened.

A grouped row is the same change, repeated: where one change was made to many packages or advisories, the advisory column says how many it stands for and opens to every one. The change is identical; it was not necessarily made in one act.

A fixed-in version is compared within one release branch: an advisory listing a fix for 4.1.x and another for 4.2.x states two, and taking the highest version across the package would report a newly added branch as though an existing branch's fix had changed.

8 more advisories that name a package in packagist had the severity changed, or the whole advisory withdrawn. None of it is counted in any figure above. Open to read it.

A severity level and a withdrawal belong to the whole advisory. The advisory database records neither against a package, so neither can be attributed to an ecosystem. These 8 rows are here for one reason: the same advisory also names a package in packagist in the table above. The other 3,172 of the 3,180 cannot be placed in an ecosystem at all.

Severity changes and withdrawals recorded against advisories that also name a package in packagist. These rows name no ecosystem of their own and are not counted in this page's ecosystem figures.
Kind of changeAdvisoryWhat changedSeverityAdvisory published
Advisory withdrawnGHSA-w42g-jj8w-fj77withdrawn 2026-06-08high2026-05-15
Advisory severity changedGHSA-5wfc-hjrc-gq87CVE-2023-34620stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.high2023-06-14
Advisory severity changedGHSA-6cpg-gqgq-2rrrCVE-2023-1761stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2023-03-31
Advisory severity changedGHSA-m648-hpf8-qcjwCVE-2020-13663stated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.high2022-05-24
Advisory severity changedGHSA-657m-v5vm-f6rwCVE-2021-41113stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2021-10-05
Advisory severity changedGHSA-rfcf-m67m-jcrqCVE-2021-32693stated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.moderate2021-06-21
Advisory severity changedGHSA-x7hc-x7fm-f7qhCVE-2021-21370stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.moderate2021-03-23
Advisory severity changedGHSA-fjh3-g8gq-9q92CVE-2021-21340stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.moderate2021-03-23

Data sources and quality

Every figure on this page counts rows keyed to a GitHub advisory, naming an ecosystem and a package; none counts CVE records or is added to the record counts elsewhere on this site. Rows, advisories and packages are three different numbers, never added.

Not checked: GitHub-reviewed advisories only. An advisory GitHub never reviewed, and an ecosystem it does not review, produce no row at all, so an ecosystem missing from these figures is not evidence that its advisories held.

How advisories are compared, in full →

Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. Not affiliated with or endorsed by GitHub.

Shipped snapshot computed 2026-09-07 from catalog commit f3250c735415. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.