packagist package report

Is typo3/cms-core safe?

126 known vulnerabilities, worst severity CRITICAL.

cvss
9.0

how bad it is if exploited, out of 10

epss
not scored

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-cc97-g92w-jm65, the advisory selected below

// advisories

GHSA-cc97-g92w-jm65

CRITICAL

Phar files (formerly known as "PHP archives") can act als self extracting archives which leads to the fact that source code is executed when Phar files are invoked. The Phar file format is not limited to be stored with a dedicated file extension - "bundle.phar" would be valid as well as "bundle.txt" would be. This way, Phar files can be obfuscated as image or text file which would not be denied fr

Affected
>= 7.0.0, < 7.6.30, >= 9.0.0, < 9.3.2, >= 8.0.0, < 8.7.17
Fixed in
7.6.30
Weakness
CWE-74
Published
2024-05-30
Source
github

GHSAreferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so packagist packages are not covered.


Checked 2026-09-22 at 00:46 UTC. The most recent advisory here was published 2026-06-12. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is typo3/cms-core safe? packagist package security report | CyberXYZ