Laravel / Framework
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-102279 | Laravel: XSS in Debug Page Information | LOW | 3.1 | Sep 28, 2026 |
| CVE-2026-48019 | CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay | HIGH | 8.9 | Sep 4, 2026 |
| CVE-2024-13919 | Laravel Reflected XSS via Route Parameter in Debug-Mode Error Page | HIGH | 8.0 | Mar 10, 2025 |
| CVE-2024-13918 | Laravel Reflected XSS via Request Parameter in Debug-Mode Error Page | HIGH | 8.0 | Mar 10, 2025 |
| CVE-2025-27515 | Laravel has a File Validation Bypass | MEDIUM | 6.9 | Mar 5, 2025 |
| CVE-2024-52301 | Laravel allows environment manipulation via query string | HIGH | 8.7 | Nov 12, 2024 |
| CVE-2024-29291 | An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed b… | n/a | Apr 16, 2024 | |
| CVE-2022-40482 | The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2… | MEDIUM | 5.3 | Apr 25, 2023 |
| CVE-2020-19316 | OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17. | HIGH | 8.8 | Dec 20, 2021 |
| CVE-2021-43808 | Blade `@parent` Exploitation Leading To Possible XSS in Laravel | MEDIUM | 6.1 | Dec 7, 2021 |
| CVE-2021-43617 | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.ph… | CRITICAL | 9.8 | Nov 14, 2021 |
| CVE-2021-21263 | Query Binding Exploitation in Laravel | HIGH | 7.2 | Jan 19, 2021 |
| CVE-2018-6330 | Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters. | HIGH | 8.8 | Mar 28, 2019 |
Showing 1 to 13 of 13 CVEs