VYPR
High severity8.0NVD Advisory· Published Mar 10, 2025· Updated Jun 17, 2026

CVE-2024-13919

CVE-2024-13919

Description

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
laravel/frameworkPackagist
>= 11.9.0, < 11.36.011.36.0

Affected products

3
  • Laravel/Framework2 versions
    cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*range: >=11.9.0,<11.36.0
    • (no CPE)range: 11.9.0
  • ghsa-coords
    Range: >= 11.9.0, < 11.36.0

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.