framework vulnerabilities
CVEs whose affected-version data names the framework package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-48019High· 8.9PoCLaravel is a web application framework
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may …
▾ Midnightlaravel · frameworkEPSS 0.68%via NVD
CVE-2026-39924Medium· 6.8Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is nev…
Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is nev…
▾ SunlitFlarum · Flarum FrameworkEPSS 0.22%via NVD