laravel
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting laravel.
- CVE-2026-48019CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay8.9
- CVE-2026-73683Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay8.1
- CVE-2026-39976Laravel Passport's TokenGuard Authenticates Unrelated User for Client Credentials Tokens7.1
- CVE-2026-23524Laravel Redis Horizontal Scaling Insecure Deserialization9.8
- CVE-2021-47756Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)8.4
- CVE-2025-54068Livewire vulnerable to remote command execution during property update hydrationKEV9.8
- CVE-2024-13919Laravel Reflected XSS via Route Parameter in Debug-Mode Error Page8.0
- CVE-2024-13918Laravel Reflected XSS via Request Parameter in Debug-Mode Error Page8.0
- CVE-2025-27515Laravel has a File Validation Bypass9.8
- CVE-2024-55661Laravel Pulse Allows Remote Code Execution via Unprotected Query Method8.8
- CVE-2024-52301Laravel allows environment manipulation via query string7.5
- CVE-2024-50347Laravel Reverb has Missing API Signature Verification
- CVE-2024-47823Livewire Remote Code Execution (RCE) on File Uploads9.8
- CVE-2024-21504Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HTML code in the con...6.1
- CVE-2024-22859Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d8873...8.8