VYPR
Medium severity6.1OSV Advisory· Published Mar 19, 2024· Updated Jun 17, 2026

CVE-2024-21504

CVE-2024-21504

Description

Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HTML code in the context of the user's browser session by crafting a malicious link and convincing the user to click on it.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
livewire/livewirePackagist
>= 3.3.5, < 3.4.93.4.9

Affected products

3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.