VendorsLaravellivewireany version
Vulnerabilities

Laravel Livewire any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-54068
Livewire vulnerable to remote command execution during property update hydration
Published 2025-07-17 · Analyzed
9.8KEVEPSS 0.971
CVE-2024-47823
Livewire Remote Code Execution (RCE) on File Uploads
Published 2024-10-08 · Analyzed
9.8EPSS 0.008
CVE-2024-22859
Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d88731 commit fixes a usability problem (HTTP 419 status codes for legitimate client activity), not a security problem.
Published 2024-02-01 · Modified
8.8EPSS 0.005
CVE-2024-21504
Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HTML code in the context of the user's browser session by crafting a malicious link and convincing the user to click on it.
Published 2024-03-19 · Analyzed
6.1EPSS 0.005