CVE-2026-102279
- EPSS 0.2%
- Veröffentlicht 28.09.2026 21:17:16
- Zuletzt bearbeitet 30.09.2026 19:38:27
Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when ...
CVE-2026-48019
- EPSS -
- Veröffentlicht 04.09.2026 22:11:40
- Zuletzt bearbeitet 10.09.2026 20:41:33
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unau...
CVE-2024-13919
- EPSS 0.51%
- Veröffentlicht 10.03.2025 10:15:13
- Zuletzt bearbeitet 24.03.2025 14:14:53
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.
CVE-2024-13918
- EPSS 0.58%
- Veröffentlicht 10.03.2025 10:15:10
- Zuletzt bearbeitet 24.03.2025 14:15:59
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.
CVE-2025-27515
- EPSS 0.72%
- Veröffentlicht 05.03.2025 19:15:39
- Zuletzt bearbeitet 26.08.2025 17:13:57
Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12....
CVE-2024-52301
- EPSS 44.3%
- Veröffentlicht 12.11.2024 20:15:14
- Zuletzt bearbeitet 26.08.2025 02:37:14
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The ...
- EPSS 1.34%
- Veröffentlicht 16.04.2024 23:15:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose t...
CVE-2022-40482
- EPSS 0.88%
- Veröffentlicht 25.04.2023 19:15:10
- Zuletzt bearbeitet 30.05.2025 19:06:45
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in t...
CVE-2020-19316
- EPSS 2.52%
- Veröffentlicht 20.12.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:08
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
CVE-2021-43808
- EPSS 0.8%
- Veröffentlicht 08.12.2021 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:50
Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user taken to anoth...