CVE security advisories and vulnerability history for framework by laravel.
18
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
9
Public exploits
With known exploit
6.8
Avg CVSS
2017–2025
Last updated
Overview
laravel framework has 18 published CVE records since 2017, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 9 have a known public exploit. The average CVSS base score across scored CVEs is 6.8.
This page aggregates every publicly disclosed vulnerability (CVE) affecting laravel framework, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of laravel framework's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical1
High4
Medium5
Low0
8 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of laravel framework's CVEs is confirmed exploited in the wild.
Public exploits
9
9 of laravel framework's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every laravel framework version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about laravel framework vulnerabilities.
How many CVEs does laravel framework have?
laravel framework has 18 published CVE records since 2017.
How many laravel framework CVEs are in CISA KEV?
Yes — 1 of laravel framework's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for laravel framework vulnerabilities?
Yes — 9 of laravel framework's CVEs have a known public exploit.
Which versions of laravel framework are affected?
1,168 distinct laravel framework versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in laravel framework CVEs?
laravel framework's CVEs most often map to these CWE weakness types: CWE-502 (Deserialization of Untrusted Data), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-203 (Observable Discrepancy), CWE-155 (Improper Neutralization of Wildcards or Matching Symbols).
How many critical laravel framework vulnerabilities are there?
laravel framework has 1 critical and 4 high-severity CVEs.
What is the average severity of laravel framework CVEs?
The average CVSS base score across laravel framework's scored CVEs is 6.8.