Laracom Project maintains a niche e-commerce platform product with a modestly defined attack surface centered on web application input handling and file-upload functionality. The observed vulnerability signal reflects recurring issues with cross-site scripting and unrestricted file uploads, which are characteristic weaknesses in web-facing commerce applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Laracom Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0472MEDIUM Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9. | Feb 4, 2022 | 5.4 | 20 | NO | NO |
CVE-2019-15489MEDIUM laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS. | Aug 26, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Laracom Project.
Media articles that mention a CVE ID that affects a product developed by Laracom Project — matched by CVE ID, not by vendor name.