Laracms Project maintains a content-management system built on the Laravel framework, with its vulnerability footprint concentrated in the core Laracms product and centered on application-layer input-handling issues such as cross-site scripting and cleartext transmission of sensitive data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Laracms Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-20128HIGH LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers. | Sep 29, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-20131MEDIUM LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows atackers to execute arbitrary web scripts or HTML via a crafted payload in the page managemen | Sep 29, 2021 | 5.4 | 20 | NO | NO |
CVE-2020-20129MEDIUM LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content edito | Sep 29, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Laracms Project.
Media articles that mention a CVE ID that affects a product developed by Laracms Project — matched by CVE ID, not by vendor name.