Laravel

Framework

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 28.09.2026 21:17:16
  • Zuletzt bearbeitet 30.09.2026 19:38:27

Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when ...

  • EPSS -
  • Veröffentlicht 04.09.2026 22:11:40
  • Zuletzt bearbeitet 10.09.2026 20:41:33

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unau...

Medienbericht Exploit
  • EPSS 0.51%
  • Veröffentlicht 10.03.2025 10:15:13
  • Zuletzt bearbeitet 24.03.2025 14:14:53

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.

Medienbericht Exploit
  • EPSS 0.58%
  • Veröffentlicht 10.03.2025 10:15:10
  • Zuletzt bearbeitet 24.03.2025 14:15:59

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.

  • EPSS 0.72%
  • Veröffentlicht 05.03.2025 19:15:39
  • Zuletzt bearbeitet 26.08.2025 17:13:57

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12....

Warnung
  • EPSS 44.3%
  • Veröffentlicht 12.11.2024 20:15:14
  • Zuletzt bearbeitet 26.08.2025 02:37:14

Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The ...

  • EPSS 1.34%
  • Veröffentlicht 16.04.2024 23:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose t...

Exploit
  • EPSS 0.88%
  • Veröffentlicht 25.04.2023 19:15:10
  • Zuletzt bearbeitet 30.05.2025 19:06:45

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in t...

Exploit
  • EPSS 2.52%
  • Veröffentlicht 20.12.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 05:09:08

OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.

Exploit
  • EPSS 0.8%
  • Veröffentlicht 08.12.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:50

Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user taken to anoth...