Catalog / Laravel

Laravel security advisories

All 9 advisories Laravel has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
96 carry a CVE
high
5
medium
3
low
1
Fix in the archive
3of 9 matched to a release
Oldest
15 Jan 20215.7 years ago

6 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2025-27515medium

File Validation Bypass

GHSA-78fx-h6xr-vch4Fixed in 12.1.1, not held here
CVE-2024-52301high

Environment manipulation via query string

GHSA-gv7v-rgg6-548hFixed in 6.20.45, not held here
CVE-2021-43808medium

Blade `@parent` Exploitation Leading To Possible XSS

GHSA-66hf-2p6w-jqfwFixed in 6.20.42, not held here
GHSA-4mg9-vhxq-vm7jhigh

SQL Server LIMIT / OFFSET SQL Injection

Fixed in 6.20.26, not held here
GHSA-x7p5-p2c9-phvghigh

Unexpected database bindings via requests (follow-up)

Fixed in 6.20.14, not held here
CVE-2021-21263high

Query Binding Exploitation

GHSA-3p32-j457-pg5x