CVE Tools

Laravel

17 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Laravel, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Laravel CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Laravel CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-020
2025-033
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical424%
  • High847%
  • Medium424%
  • Low16%

Latest CVEs

The 15 most recently published vulnerabilities affecting Laravel.

  1. CVE-2024-13919Laravel Reflected XSS via Route Parameter in Debug-Mode Error Page8.0
  2. CVE-2024-13918Laravel Reflected XSS via Request Parameter in Debug-Mode Error Page8.0
  3. CVE-2025-27515Laravel has a File Validation Bypass9.8
  4. CVE-2024-52301Laravel allows environment manipulation via query string7.5
  5. CVE-2024-29291An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the o...3.5
  6. CVE-2021-28254A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.9.8
  7. CVE-2022-2886Laravel deserialization5.0
  8. CVE-2022-2870laravel deserialization4.1
  9. CVE-2021-43617Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which...9.8
  10. CVE-2021-21263Query Binding Exploitation in Laravel7.2
  11. CVE-2021-3129Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_content...9.8
  12. CVE-2020-24940An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.7.5
  13. CVE-2020-24941An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.7.5
  14. CVE-2018-15133In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the d...8.1
  15. CVE-2017-16894In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Lar...7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store