| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-39976 | Laravel Passport's TokenGuard Authenticates Unrelated User for Client Credentials Tokens | laravel | passport | High | 7.1 | 2026-04-09 16:50:42 | Deep Dive |
| CVE-2019-25673 | UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File Upload | UniSharp | Laravel File Manager | High | 8.8 | 2026-04-05 20:45:26 | Deep Dive |
| CVE-2026-5370 | krayin laravel-crm Activities Module/Notes inbox.spec.ts composeMail cross site scripting | krayin | laravel-crm | Low | 3.5 | 2026-04-02 17:30:15 | Deep Dive |
| CVE-2026-4809 | Unsafe Client MIME Type Handling Can Enable Arbitrary File Upload in plank/laravel-mediable | plank | laravel-mediable | Critical | 9.8 | 2026-03-26 11:03:27 | Deep Dive |
| CVE-2020-36950 | Laravel Nova 3.7.0 - 'range' DoS | Laravel Holdings Inc. | Laravel Nova | Medium | 6.5 | 2026-01-27 15:23:51 | Deep Dive |
| CVE-2026-23524 | Laravel Redis Horizontal Scaling Insecure Deserialization | laravel | reverb | Critical | 9.8 | 2026-01-21 22:07:56 | Deep Dive |
| CVE-2021-47756 | Laravel Valet 2.0.3 - Local Privilege Escalation (macOS) | Laravel | Laravel Valet | High | 8.4 | 2026-01-15 23:25:36 | Deep Dive |
| CVE-2021-47763 | Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection | Aimeos | Aimeos Laravel ecommerce platform | High | 8.2 | 2026-01-15 15:52:08 | Deep Dive |
| CVE-2025-58769 | auth0-PHP: Improper File Type Handling in Bulk User Import | auth0 | laravel-auth0 | Low | 3.3 | 2025-10-01 19:57:06 | Deep Dive |
| CVE-2025-49130 | Laravel Translation Manager Vulnerable to Stored Cross-site Scripting | barryvdh | laravel-translation-manager | - | - | 2025-06-09 12:49:38 | Deep Dive |
| CVE-2025-48490 | Laravel Rest Api has a Search Validation Bypass | Lomkit | laravel-rest-api | - | - | 2025-05-30 05:28:00 | Deep Dive |
| CVE-2024-13919 | Laravel Reflected XSS via Route Parameter in Debug-Mode Error Page | Laravel Holdings Inc. | Laravel Framework | High | 8.0 | 2025-03-10 10:03:01 | Deep Dive |
| CVE-2024-13918 | Laravel Reflected XSS via Request Parameter in Debug-Mode Error Page | Laravel Holdings Inc. | Laravel Framework | High | 8.0 | 2025-03-10 10:02:30 | Deep Dive |
| CVE-2025-27515 | Laravel has a File Validation Bypass | laravel | framework | 中危 | - | 2025-03-05 18:45:50 | Deep Dive |
| CVE-2024-21546 | laravel-filemanager 安全漏洞 | - | unisharp/laravel-filemanager | Critical | 9.8 | 2024-12-18 06:06:03 | Deep Dive |
| CVE-2024-55661 | Laravel Pulse Allows Remote Code Execution via Unprotected Query Method | laravel | pulse | 高危 | - | 2024-12-13 16:04:52 | Deep Dive |
| CVE-2024-52306 | FileManager Deserialization of Untrusted Data | Laravel-Backpack | FileManager | High | 7.6 | 2024-11-13 15:15:38 | Deep Dive |
| CVE-2024-52301 | Laravel allows environment manipulation via query string | laravel | framework | - | - | 2024-11-12 19:32:14 | Deep Dive |
| CVE-2024-50347 | Laravel Reverb has Missing API Signature Verification | laravel | reverb | 中危 | - | 2024-10-31 17:56:42 | Deep Dive |
| CVE-2024-7945 | itsourcecode Laravel Property Management System Notes Page create cross site scripting | itsourcecode | Laravel Property Management System | Low | 3.5 | 2024-08-20 01:00:08 | Deep Dive |