Framework
by Laravel
Source repositories
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-43617 | Cri | 0.68 | 9.8 | 0.20 | Nov 14, 2021 | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE… | ||
| CVE-2025-27515 | Cri | 0.57 | 9.8 | 0.01 | Mar 5, 2025 | Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1. | ||
| CVE-2018-6330 | Hig | 0.57 | 8.8 | 0.02 | Mar 28, 2019 | Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters. | ||
| CVE-2024-52301 | Hig | 0.52 | 7.5 | 0.44 | Nov 12, 2024 | Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in… | ||
| CVE-2020-19316 | Hig | 0.50 | 8.8 | 0.03 | Dec 20, 2021 | OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17. | ||
| CVE-2024-13919 | Hig | 0.45 | 8.0 | 0.01 | Mar 10, 2025 | The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page. | ||
| CVE-2024-13918 | Hig | 0.45 | 8.0 | 0.01 | Mar 10, 2025 | The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page. | ||
| CVE-2021-43808 | Med | 0.28 | 5.3 | 0.01 | Dec 8, 2021 | Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user taken to another location in their browser… | ||
| CVE-2022-40482 | Med | 0.00 | 5.3 | 0.01 | Apr 25, 2023 | The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the… |
- risk 0.68cvss 9.8epss 0.20
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE…
- risk 0.57cvss 9.8epss 0.01
Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.
- risk 0.57cvss 8.8epss 0.02
Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.
- risk 0.52cvss 7.5epss 0.44
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in…
- risk 0.50cvss 8.8epss 0.03
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
- risk 0.45cvss 8.0epss 0.01
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.
- risk 0.45cvss 8.0epss 0.01
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.
- risk 0.28cvss 5.3epss 0.01
Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user taken to another location in their browser…
- risk 0.00cvss 5.3epss 0.01
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the…