Skip to main content

Vendor archive

laravel CVEs

Beta · best-effort

28 CVEs tagged to vendor laravel5 Critical, 15 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-39976

Published Apr 9, 2026

Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server…

CVSS 7.1 · High
evidence mentions
5
Buzz score
27.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-23524

Published Jan 21, 2026

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2025-54068

Published Jul 17, 2025

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-13919

Published Mar 10, 2025

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13918

Published Mar 10, 2025

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode err…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27515

Published Mar 5, 2025

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypa…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-55661

Published Dec 13, 2024

Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in Laravel Pulse prior to version…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52301

Published Nov 12, 2024

Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to chang…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47823

Published Oct 8, 2024

Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension o…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21504

Published Mar 19, 2024

Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HT…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22859

Published Feb 1, 2024

Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40482

Published Apr 25, 2023

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28254

Published Apr 19, 2023

A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-2886

Published Aug 19, 2022

A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2870

Published Aug 17, 2022

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be in…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25838

Published Feb 24, 2022

Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43808

Published Dec 8, 2021

Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating e…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43617

Published Nov 14, 2021

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21263

Published Jan 19, 2021

Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/dat…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3129

Published Jan 12, 2021

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() an…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
57.4
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2020-24941

Published Sep 4, 2020

An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting express…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24940

Published Sep 4, 2020

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6330

Published Mar 28, 2019

Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15133

Published Aug 9, 2018

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. T…

CVSS 8.1 · High
evidence mentions
3
Buzz score
46.9
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2