Spatie is a software development company whose vulnerability footprint centers on two modestly deployed web and media-handling libraries: Browsershot, a headless-browser wrapper, and Laravel Media Library, a file-management component for the Laravel framework. The recurring weakness classes—cross-site scripting, path traversal, and unrestricted file uploads—reflect the input-handling and filesystem-access demands of web application tooling; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spatie over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45040CRITICAL The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route. | Mar 17, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-43984HIGH Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content impo | Nov 25, 2022 | 8.2 | 27 | NO | NO |
CVE-2022-41706HIGH Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed | Nov 25, 2022 | 8.2 | 26 | NO | NO |
CVE-2022-43983HIGH Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content pa | Nov 25, 2022 | 8.2 | 26 | NO | NO |
CVE-2020-7790MEDIUM This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF. | Dec 11, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spatie.
Media articles that mention a CVE ID that affects a product developed by Spatie — matched by CVE ID, not by vendor name.