Laravel Admin is an administrative dashboard library for the Laravel PHP framework, presenting a niche but notably present attack surface within Laravel application deployments. The observed vulnerabilities center on the product itself without a clearly recurring weakness class signal at this volume. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Laravel Admin over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24249HIGH An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file. | Feb 27, 2023 | 7.2 | 24 | NO | NO |
CVE-2019-17433MEDIUM z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen. | Oct 10, 2019 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Laravel Admin.
Media articles that mention a CVE ID that affects a product developed by Laravel Admin — matched by CVE ID, not by vendor name.