VYPR

LaraDashboard

by LaraDashboard

CVEs (2)

  • CVE-2026-86184CriSep 5, 2026
    risk 0.57cvss 9.8epss

    Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint…

  • CVE-2025-66509CriDec 4, 2025
    risk 0.00cvss 9.8epss 0.00

    LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be combined with the module…