Package Health

concrete5/core

Concrete core subtree split

Latest 9.5.0RC2PackagistPackagist

100%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Vulnerabilities

TitleVersionsSeverity
CVE-2022-21829
concrete5/core is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 9.0.0 - 9.1.0 and 0.0.0 - 8.5.8.
0.0.0 - 8.5.89.0.0 - 9.1.0
High
CVE-2022-30120
concrete5/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 9.0.0 - 9.1.0 and 0.0.0 - 8.5.8.
0.0.0 - 8.5.89.0.0 - 9.1.0
Low
CVE-2022-30117
concrete5/core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 9.0.0 - 9.1.0 and 0.0.0 - 8.5.8.
0.0.0 - 8.5.89.0.0 - 9.1.0
Critical
CVE-2021-22968
concrete5/core is vulnerable to Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in versions 0.0.0 - 8.5.7.
0.0.0 - 8.5.7
High
CVE-2021-22970
concrete5/core is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 8.5.7.
0.0.0 - 8.5.7
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.11
league/csv
Version ^9.7.1
league/url
Version ~3.3.5
punic/punic
Version ^3.0.1
doctrine/orm
Version ^2.13

Weekly Downloads

Info

Last Published
21 hours ago
Created
8 years ago