Skip to main content

Vendor/product archive

laravel / framework CVEs

Beta · best-effort

9 CVEs tagged to laravel / framework1 Critical, 5 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-13919

Published Mar 10, 2025

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13918

Published Mar 10, 2025

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode err…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27515

Published Mar 5, 2025

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypa…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-52301

Published Nov 12, 2024

Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to chang…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40482

Published Apr 25, 2023

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43808

Published Dec 8, 2021

Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating e…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43617

Published Nov 14, 2021

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6330

Published Mar 28, 2019

Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1