Build a fully-featured hypermedia or GraphQL API in minutes!
88%
Total Score
100
63
80
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-49858 New api-platform/core is vulnerable to Use of Cache Containing Sensitive Information in versions 2.6.0 - 4.1.29, 4.2.0 - 4.2.25 and 4.3.0 - 4.3.8. | 2.6.0 - 4.1.294.2.0 - 4.2.254.3.0 - 4.3.8 | Medium |
AIKIDO-2026-10459 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. api-platform/core is vulnerable to Improper Authorization in versions 4.3.0 - 4.3.0 and 4.2.0 - 4.2.21. | 4.2.0 - 4.2.214.3.0 - 4.3.0 | High |
AIKIDO-2026-10398 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. api-platform/core is vulnerable to Information Disclosure in versions 3.1.0 - 4.2.21. | 3.1.0 - 4.2.21 | Medium |
CVE-2023-47639 api-platform/core is vulnerable to Generation of Error Message Containing Sensitive Information in versions 3.2.0 - 3.2.5. | 3.2.0 - 3.2.5 | Medium |
CVE-2025-23204 api-platform/core is vulnerable to Improper Input Validation in versions 3.3.8 - 3.3.15. | 3.3.8 - 3.3.15 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
composer/semver Version ^3.4 | — | — |
symfony/web-link Version ^7.4 || ^8.0 | — | — |
symfony/type-info Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant