Skip to main content

Vendor/product archive

laravel / livewire CVEs

Beta · best-effort

4 CVEs tagged to laravel / livewire1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-54068

Published Jul 17, 2025

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-47823

Published Oct 8, 2024

Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension o…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21504

Published Mar 19, 2024

Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HT…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22859

Published Feb 1, 2024

Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1