Laravel
Laravel Framework: vulnerabilidades y CVE
Laravel Framework tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-13919 | Media (6.1) | 0.52% | — | 10 mar 2025 | The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page. |
| CVE-2024-13918 | Media (6.1) | 0.59% | — | 10 mar 2025 | The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page. |
| CVE-2025-27515 | Media (6.9) | 0.75% | — | 5 mar 2025 | Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This… |
| CVE-2024-52301 | Alta (8.7) | 45% | — | 12 nov 2024 | Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework… |
| CVE-2024-29291 | Sin puntuar | 1.3% | — | 16 abr 2024 | An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel… |
| CVE-2022-40482 | Media (5.3) | 0.89% | — | 25 abr 2023 | The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the… |
| CVE-2020-19316 | Alta (8.8) | 2.5% | — | 20 dic 2021 | OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17. |
| CVE-2021-43808 | Media (6.1) | 0.83% | — | 8 dic 2021 | Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be… |
| CVE-2021-43617 | Crítica (9.8) | 20% | — | 14 nov 2021 | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as… |
| CVE-2018-6330 | Alta (8.8) | 1.6% | — | 28 mar 2019 | Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters. |