Laravel/framework
This hub aggregates every CVE we track for Laravel/framework, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
25
CVEs tracked
2
Critical
7
High
1
In CISA KEV
Severity distribution
HIGH7MEDIUM3CRITICAL2
Monthly trend
0
1
0
0
0
3
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Laravel/framework.
- GHSA-crmm-hgp2-wgrpLaravel Framework: Temporary Signed URL Path Confusion
- GHSA-5vg9-5847-vvmqLaravel Framework: CRLF injection in default email rule
- CVE-2024-13919Laravel Reflected XSS via Route Parameter in Debug-Mode Error Page8.0
- CVE-2024-13918Laravel Reflected XSS via Request Parameter in Debug-Mode Error Page8.0
- CVE-2025-27515Laravel has a File Validation Bypass9.8
- CVE-2024-52301Laravel allows environment manipulation via query string7.5
- GHSA-wq8p-mqvg-2p5hlaravel framework SQL Injection via limit and offset functions
- GHSA-jwvj-pwww-3mj5laravel framework Unexpected database bindings via requests
- GHSA-44pg-c29v-hp6rLaravel Guard bypass in Eloquent models
- GHSA-qm5c-m76r-2hfrLaravel RCE vulnerability in "cookie" session driver
- GHSA-vr95-p7q6-8m9qLaravel Cross-site Scripting (XSS) vulnerability in blade templating
- GHSA-6jvx-8ch9-j2jrLaravel Cookie serialization vulnerability
- GHSA-7852-w36x-6mf6Laravel Encrypter Component Potential Decryption Failure Leading to Unintended Behavior
- GHSA-p62r-7637-3wwcLaravel Hijacked authentication cookies vulnerability
- GHSA-rj3w-99gc-8j58Laravel Risk of mass-assignment vulnerabilities
Product normalization is registry-driven with AI assist and human review. How it works