VendorsLaravelframeworkall versions
Vulnerabilities

Laravel Framework

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-43617
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.
Published 2021-11-14 · Modified
9.81 PoCEPSS 0.198
CVE-2025-27515
Laravel has a File Validation Bypass
Published 2025-03-05 · Analyzed
9.8EPSS 0.007
CVE-2020-19316
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
Published 2021-12-20 · Modified
8.8EPSS 0.025
CVE-2018-6330
Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.
Published 2019-03-28 · Modified
8.8EPSS 0.016
CVE-2024-52301
Laravel allows environment manipulation via query string
Published 2024-11-12 · Analyzed
8.7EPSS 0.448
CVE-2024-13918
Laravel Reflected XSS via Request Parameter in Debug-Mode Error Page
Published 2025-03-10 · Analyzed
8.0EPSS 0.006
CVE-2024-13919
Laravel Reflected XSS via Route Parameter in Debug-Mode Error Page
Published 2025-03-10 · Analyzed
8.0EPSS 0.005
CVE-2021-43808
Blade `@parent` Exploitation Leading To Possible XSS in Laravel
Published 2021-12-07 · Modified
6.1EPSS 0.008
CVE-2022-40482
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.
Published 2023-04-25 · Analyzed
5.3EPSS 0.009