Laravel/framework
25 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Laravel/framework, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Laravel/framework CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 3 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 2 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High7
- Medium3
Latest CVEs
The 15 most recently published vulnerabilities affecting Laravel/framework.
- GHSA-crmm-hgp2-wgrpLaravel Framework: Temporary Signed URL Path Confusion—
- GHSA-5vg9-5847-vvmqLaravel Framework: CRLF injection in default email rule —
- CVE-2024-13919Laravel Reflected XSS via Route Parameter in Debug-Mode Error Page8.0
- CVE-2024-13918Laravel Reflected XSS via Request Parameter in Debug-Mode Error Page8.0
- CVE-2025-27515Laravel has a File Validation Bypass9.8
- CVE-2024-52301Laravel allows environment manipulation via query string7.5
- GHSA-wq8p-mqvg-2p5hlaravel framework SQL Injection via limit and offset functions—
- GHSA-jwvj-pwww-3mj5laravel framework Unexpected database bindings via requests—
- GHSA-44pg-c29v-hp6rLaravel Guard bypass in Eloquent models—
- GHSA-qm5c-m76r-2hfrLaravel RCE vulnerability in "cookie" session driver—
- GHSA-vr95-p7q6-8m9qLaravel Cross-site Scripting (XSS) vulnerability in blade templating—
- GHSA-6jvx-8ch9-j2jrLaravel Cookie serialization vulnerability—
- GHSA-7852-w36x-6mf6Laravel Encrypter Component Potential Decryption Failure Leading to Unintended Behavior—
- GHSA-p62r-7637-3wwcLaravel Hijacked authentication cookies vulnerability—
- GHSA-rj3w-99gc-8j58Laravel Risk of mass-assignment vulnerabilities—
Product grouping is registry-driven, with AI assist and human review. How it works