Exposição de Laravel

Web frameworks
79
score de exposição
100.469
sites usam
0
em exploração
3
críticos
Análise Vexday

O histórico de vulnerabilidades do Laravel reúne 31 CVEs catalogadas, com duas classificadas como críticas e nenhuma presente no catálogo KEV da CISA, taxa que se mantém abaixo da média geral do catálogo. O volume recente merece atenção: 11 falhas surgiram nos últimos 90 dias, o que indica ritmo elevado de descoberta e exige acompanhamento contínuo de atualizações. O tipo de falha mais recorrente é CWE-434 (upload irrestrito de arquivos com tipo perigoso), categoria que, quando explorada, pode permitir execução remota de código e comprometer completamente aplicações. A CVE mais perigosa atualmente identificada é CVE-2021-23814, com EPSS de 0,0182, sugerindo probabilidade de exploração ainda baixa, mas não desprezível diante da natureza da falha dominante no perfil do framework.

CVEs

45 resultados
CVE-2026-41452CRITICALKrayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setupEPSS 2.5%CVE-2021-23814MEDIUMThis affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the filEPSS 1.8%CVE-2024-21546CRITICALVersions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetyEPSS 1.3%CVE-2026-49972HIGHLaravel-Mediable < 7.0.0 File Upload RCE via Extension BypassEPSS 1.1%CVE-2026-49970HIGHLaravel-Mediable < 7.0.0 Path Traversal via File::sanitizePath()EPSS 1.0%CVE-2026-53932HIGHwnx/laravel-backup-restore: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') and Improper Neutralization of Special Elements used in a Command ('Command Injection')EPSS 0.9%CVE-2026-4809CRITICALUnsafe Client MIME Type Handling Can Enable Arbitrary File Upload in plank/laravel-mediableEPSS 0.9%CVE-2022-2870MEDIUMlaravel deserializationEPSS 0.8%CVE-2024-7067MEDIUMkirilkirkov Ecommerce-Laravel-Bootstrap Cart.php getCartProductsIds deserializationEPSS 0.8%CVE-2026-90944HIGHKrayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parseEPSS 0.7%CVE-2024-7943MEDIUMitsourcecode Laravel Property Management System PropertiesController.php upload unrestricted uploadEPSS 0.7%CVE-2022-2886MEDIUMLaravel deserializationEPSS 0.7%CVE-2024-6056MEDIUMnasirkhan Laravel Starter Password Reset forgot-password observable response discrepancyEPSS 0.7%CVE-2021-4262MEDIUMlaravel-jqgrid EloquentRepositoryAbstract.php getRows sql injectionEPSS 0.6%CVE-2025-48490MEDIUMLaravel Rest Api has a Search Validation BypassEPSS 0.6%CVE-2024-7495MEDIUMitsourcecode Laravel Accounting System HomeController.php unrestricted uploadEPSS 0.6%CVE-2024-13918HIGHLaravel Reflected XSS via Request Parameter in Debug-Mode Error PageEPSS 0.6%CVE-2026-84374HIGHLaravel Excel writes exports outside the configured filesystem disk when given a caller-controlled pathEPSS 0.6%CVE-2024-13919HIGHLaravel Reflected XSS via Route Parameter in Debug-Mode Error PageEPSS 0.5%CVE-2026-61701HIGHLaravel MagicLink: Insecure Deserialization of MagicLink Actions Leads to Remote Code ExecutionEPSS 0.5%