Framework
Vendor:
First CVE: Mar 28, 2019 · Active for 7 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Framework over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2019
7 years ago
Most Recent CVE
Mar 10, 2025
501 days ago
CVE Severity & Scoring
Framework9 CVEs
44%
33%
22%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43617CRITICAL Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for . | Nov 14, 2021 | 9.8 | 52 | NO | YES |
CVE-2024-52301HIGH Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change | Nov 12, 2024 | 7.5 | 37 | NO | NO |
CVE-2025-27515CRITICAL Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypas | Mar 5, 2025 | 9.8 | 28 | NO | NO |
CVE-2018-6330HIGH Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters. | Mar 28, 2019 | 8.8 | 28 | NO | NO |
CVE-2024-13919MEDIUM The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error | Mar 10, 2025 | 6.1 | 22 | NO | NO |
CVE-2024-13918MEDIUM The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode erro | Mar 10, 2025 | 6.1 | 22 | NO | NO |
CVE-2020-19316HIGH OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17. | Dec 20, 2021 | 8.8 | 22 | NO | NO |
CVE-2021-43808MEDIUM Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating en | Dec 8, 2021 | 6.1 | 22 | NO | NO |
CVE-2022-40482MEDIUM The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is | Apr 25, 2023 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Framework
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.4.15 | 1 | 8.8 | 1.6% | 0 | 0 |