VulnSea

laradashboard has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 8. The median CVSS is 7.2 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-862 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.2
Publish → KEV
Last 90 days
8 prev 0

Products

  • laradashboard 8
8
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

laradashboard vulnerabilities

CVEs affecting laradashboard, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-90932High· 7.2PoC
1w ago

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file…

Midnightlaradashboard · laradashboardEPSS 0.46%via NVD
CVE-2026-90931Medium· 5.4PoC
1w ago

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user incl…

Twilightlaradashboard · laradashboardEPSS 0.17%via NVD
CVE-2026-90933High· 7.1PoC
1w ago

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged ac…

Midnightlaradashboard · laradashboardEPSS 0.22%via NVD
CVE-2026-87821High· 7.1PoC
1w ago

Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body

Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can…

Midnightlaradashboard · laradashboardEPSS 0.33%via NVD
CVE-2026-86438High· 7.2
2w ago

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the…

Twilightlaradashboard · laradashboardEPSS 0.60%via NVD
CVE-2026-86437High· 7.2PoC
2w ago

Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live appli…

Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live appli…

Midnightlaradashboard · laradashboardEPSS 0.39%via NVD
CVE-2026-86436Medium· 5.4PoC
2w ago

Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files

Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-ch…

Twilightlaradashboard · laradashboardEPSS 0.30%via NVD
CVE-2026-86184Critical· 9.8
2w ago

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request th…

Midnightlaradashboard · laradashboardEPSS 0.60%via NVD
laradashboard vulnerabilities (CVEs) · VulnSea