laravel has 3 CVEs on record. 1 was published in the last 90 days. The median CVSS is 8.9 (high). Most affected products: laravel/framework (2), framework (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.9
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
laravel vulnerabilities
CVEs affecting laravel, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-48019High· 8.9PoCLaravel is a web application framework
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may …
▾ Midnightlaravel · frameworkEPSS 0.68%via NVD
GHSA-5vg9-5847-vvmqHigh· 8.9Laravel Framework: CRLF injection in default email rule
Laravel Framework: CRLF injection in default email rule
▾ Twilightlaravel · laravel/frameworkvia GHSA
GHSA-crmm-hgp2-wgrpMedium· 4.2Laravel Framework: Temporary Signed URL Path Confusion
Laravel Framework: Temporary Signed URL Path Confusion
▾ Sunlitlaravel · laravel/frameworkvia GHSA