Alexusmai develops the Laravel File Manager, a file-management component for PHP applications, where the observed vulnerability pattern centers on path-traversal and cross-site scripting flaws arising from input validation and output-encoding gaps. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alexusmai over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65346CRITICAL alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrar | Dec 4, 2025 | 9.1 | 26 | NO | NO |
CVE-2025-63307HIGH alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types | Nov 6, 2025 | 8.1 | 25 | NO | NO |
CVE-2025-65345MEDIUM alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and dire | Dec 3, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alexusmai.
Media articles that mention a CVE ID that affects a product developed by Alexusmai — matched by CVE ID, not by vendor name.