Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Passport HIGH 7.1
CVE-2026-39976

Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials to…

Fix: 13.7.1+
Fix from $1,950 2026-04-09
Reverb CRITICAL 9.8
CVE-2026-23524

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from th…

Fix: 1.7.0+
Fix from $2,300 2026-01-21
Livewire CRITICAL 9.8
CVE-2025-54068 KEVEPSS 96%

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achiev…

Fix: 3.6.4+
Fix from $2,300 2025-07-17
Framework MEDIUM 6.1
CVE-2024-13919

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route para…

Fix: 11.36.0+
Fix from $1,600 2025-03-10
Framework MEDIUM 6.1
CVE-2024-13918

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request pa…

Fix: 11.36.0+
Fix from $1,600 2025-03-10
Framework CRITICAL 9.8
CVE-2025-27515

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious …

Fix: 11.44.1 / 12.1.1+
Fix from $2,300 2025-03-05
Pulse HIGH 8.8
CVE-2024-55661EPSS 29%

Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in L…

Fix: 1.3.1+
Fix from $1,950 2024-12-13
Framework HIGH 7.5
CVE-2024-52301EPSS 44%

Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query …

Fix: 6.20.45 / 7.30.7+
Fix from $1,950 2024-11-12
Livewire CRITICAL 9.8
CVE-2024-47823

Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and …

Fix: 2.12.7 / 3.5.2+
Fix from $2,300 2024-10-08
Livewire MEDIUM 6.1
CVE-2024-21504

Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a prope…

Fix: after 3.4.9
Fix from $1,600 2024-03-19
Livewire HIGH 8.8
CVE-2024-22859

Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. N…

Fix: 3.0.4+
Fix from $1,950 2024-02-01
Framework MEDIUM 5.3
CVE-2022-40482

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks wi…

Fix: 8.83.24 / 9.32.0+
Fix from $1,600 2023-04-25
Laravel CRITICAL 9.8
CVE-2021-28254

A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.

No fix yet
Fix from $2,300 2023-04-19
Laravel HIGH 8.8
CVE-2022-2886

A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserializati…

Fix: after 5.1.46
Fix from $1,950 2022-08-19
Laravel CRITICAL 9.8
CVE-2022-2870

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deseria…

Fix: after 5.1.46
Fix from $2,300 2022-08-17
Fortify HIGH 8.1
CVE-2022-25838

Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.

Fix: 1.11.1+
Fix from $1,950 2022-02-24
Framework HIGH 8.8
CVE-2020-19316

OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.

Fix: 5.8.17+
Fix from $1,950 2021-12-20
Framework MEDIUM 6.1
CVE-2021-43808

Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerabi…

Fix: 6.20.42 / 7.30.6+
Fix from $1,600 2021-12-08
Framework CRITICAL 9.8
CVE-2021-43617EPSS 20%

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAtt…

Fix: after 8.70.2
Fix from $2,300 2021-11-14
Laravel MEDIUM 5.3
CVE-2021-21263

Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit…

Fix: 6.20.11 / 7.30.2+
Fix from $1,600 2021-01-19
Laravel HIGH 7.5
CVE-2020-24940

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which tab…

Fix: 6.18.34 / 7.23.2+
Fix from $1,950 2020-09-04
Laravel HIGH 7.5
CVE-2020-24941

An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests wi…

Fix: 6.18.35 / 7.24.0+
Fix from $1,950 2020-09-04
Framework HIGH 8.8
CVE-2018-6330

Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.

No fix yet
Fix from $1,950 2019-03-28
Laravel HIGH 8.1
CVE-2018-15133 KEVEPSS 77%

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially u…

Fix: after 5.6.29
Fix from $1,950 2018-08-09
Laravel HIGH 7.5
CVE-2017-16894EPSS 87%

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for…

Fix: after 5.5.21
Fix from $1,950 2017-11-20
Laravel MEDIUM 5.9
CVE-2017-14775

Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.

Fix: after 5.5.9
Fix from $1,600 2017-09-28
Laravel MEDIUM 6.1
CVE-2017-9303

Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to condu…

Mitigation only
Fix from $1,600 2017-05-29