laravel/framework vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the laravel/framework package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Authentication Bypass

<8.83.24
  • C
Command Injection

<5.8.17
  • M
Cross-site Scripting (XSS)

<6.20.42 >=7.0.0, <7.30.6 >=8.0.0, <8.75.0
  • H
Improper Input Validation

>=0.0.0, <6.20.42 >=7.0.0, <7.30.6 >=8.0.0, <8.73.0
  • H
SQL Injection

<6.20.26 >=8.0.0, <8.40.0
  • M
Resource Management Errors

<6.20.14 >=7.0.0, <7.30.4 >=8.0.0, <8.24.0
  • M
Resource Management Errors

>=6.0.0, <6.20.12 >=7.0.0, <7.30.3 >=8.0.0, <8.22.1
  • H
SQL Injection

>=6.0.0, <6.20.11 >=7.0.0, <7.30.2 >=8.0.0, <8.22.1
  • H
Improper Input Validation

<6.18.34 >=7.0.0, <7.23.2
  • M
Cryptographic Issues

<6.18.29 >7.0.0, <7.22.2
  • M
Cross-site Scripting (XSS)

>=7.0.0, <7.1.2
  • M
Remote Code Execution (RCE)

>=5.6.0, <5.6.30 <5.5.41
  • M
Improper Password Reset Constraints

>=5.4.0, <5.4.22 >=5.3.0, <=5.3.31
  • L
Encryption Failure

>=5.1.0, <=5.1.46 >=5.0.0, <=5.0.35 >=5.5.0, <5.5.40 >=5.3.0, <=5.3.31 >=4.1.0, <=4.1.31 >=4.0.0, <=4.0.11 >=5.4.0, <=5.4.36 >=4.2.0, <=4.2.22 >=5.2.0, <=5.2.45 >=5.6.0, <5.6.15
  • H
Authentication Cookie Hijacking

<4.1.26
  • M
Mass Assignment

>=4.1.0, <4.1.29
  • M
Timing Attack

<5.5.10
  • H
Information Exposure

<5.5.22
  • M
Mass Assignment

<4.1.29
  • H
Authentication Cookie Hijacking

<4.1.26