Laravel is a widely deployed PHP web-application framework whose compact product portfolio punches above its volume in the vulnerability landscape, reflecting its prominence as a foundational dependency across countless web services and applications. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have an elevated tendency toward confirmed in-the-wild exploitation and public exploit availability, consistent with the high value of framework-level flaws that propagate to all downstream applications. The exposure recurs across the framework itself and supporting packages such as Livewire, Fortify, and Pulse, concentrating in weakness classes including untrusted deserialization, cross-site scripting, input validation, code injection, and sensitive-information exposure that are endemic to server-side template engines and request-handling pipelines. Because Laravel sits deep in the application layer, a single vulnerability can affect thousands of dependent applications simultaneously; defenders should monitor this vendor's release cycles closely and prioritize framework updates in their deployment infrastructure. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Laravel over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3129CRITICAL Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and | Jan 12, 2021 | 9.8 | 99 | YES | YES |
CVE-2025-54068CRITICAL Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in s | Jul 17, 2025 | 9.8 | 98 | YES | YES |
CVE-2018-15133HIGH In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. Th | Aug 9, 2018 | 8.1 | 97 | YES | YES |
CVE-2017-16894HIGH In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE | Nov 20, 2017 | 7.5 | 90 | NO | YES |
CVE-2024-55661HIGH Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in Laravel Pulse prior to version 1 | Dec 13, 2024 | 8.8 | 54 | NO | YES |
CVE-2021-43617CRITICAL Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for . | Nov 14, 2021 | 9.8 | 52 | NO | YES |
CVE-2024-52301HIGH Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change | Nov 12, 2024 | 7.5 | 37 | NO | NO |
CVE-2026-23524CRITICAL Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into P | Jan 21, 2026 | 9.8 | 34 | NO | NO |
CVE-2024-47823CRITICAL Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of | Oct 8, 2024 | 9.8 | 30 | NO | NO |
CVE-2021-28254CRITICAL A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands. | Apr 19, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Laravel.
Media articles that mention a CVE ID that affects a product developed by Laravel — matched by CVE ID, not by vendor name.