Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Laravel

First CVE: May 29, 2017Active for: 9 yearsTotal CVEs: 28
77.0
VTI Score
TOP TARGET

Laravel is a widely deployed PHP web-application framework whose compact product portfolio punches above its volume in the vulnerability landscape, reflecting its prominence as a foundational dependency across countless web services and applications. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have an elevated tendency toward confirmed in-the-wild exploitation and public exploit availability, consistent with the high value of framework-level flaws that propagate to all downstream applications. The exposure recurs across the framework itself and supporting packages such as Livewire, Fortify, and Pulse, concentrating in weakness classes including untrusted deserialization, cross-site scripting, input validation, code injection, and sensitive-information exposure that are endemic to server-side template engines and request-handling pipelines. Because Laravel sits deep in the application layer, a single vulnerability can affect thousands of dependent applications simultaneously; defenders should monitor this vendor's release cycles closely and prioritize framework updates in their deployment infrastructure. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
10.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Laravel over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2017
9 years ago
Most Recent CVE
Apr 9, 2026
106 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3129CRITICAL
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and
Jan 12, 20219.899YESYES
CVE-2025-54068CRITICAL
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in s
Jul 17, 20259.898YESYES
CVE-2018-15133HIGH
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. Th
Aug 9, 20188.197YESYES
CVE-2017-16894HIGH
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE
Nov 20, 20177.590NOYES
CVE-2024-55661HIGH
Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in Laravel Pulse prior to version 1
Dec 13, 20248.854NOYES
CVE-2021-43617CRITICAL
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .
Nov 14, 20219.852NOYES
CVE-2024-52301HIGH
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change
Nov 12, 20247.537NONO
CVE-2026-23524CRITICAL
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into P
Jan 21, 20269.834NONO
CVE-2024-47823CRITICAL
Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of
Oct 8, 20249.830NONO
CVE-2021-28254CRITICAL
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.
Apr 19, 20239.830NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
29%
43%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (85.7%)
High4 (14.3%)
Unknown0 (0.0%)
User Interaction
None19 (67.9%)
Unknown0 (0.0%)
Required9 (32.1%)
Privileges Required
Low2 (7.1%)
High0 (0.0%)
None26 (92.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
3 CVEs
10.7% of CVEs· 100th percentile
Metasploit
3 CVEs
10.7% of CVEs· 98th percentile
Nuclei
3 CVEs
10.7% of CVEs· 96th percentile
ExploitDB
5 CVEs
17.9% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Laravel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Laravel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Laravel's Products

View all 5 CNAs →

Top CWEs