PROFILE
CategoryvendorWhat they doLaravel is a web application framework for PHP that provides a robust set of tools for developing web applications and APIs.
Websitehttps://laravel.com/ ↗
SECURITY POSTURE
Laravel has been identified with multiple security vulnerabilities, indicating a potential lack of robust security practices during development and maintenance.
Notable failures
- CVE-2025-54068: High (RCE) - Unauthenticated attackers could execute remote commands via code injection.
- CVE-2021-3129: Critical (RCE) - Unauthenticated attackers could execute arbitrary code via a file upload vulnerability in Laravel Ignition.
- CVE-2018-15133: High (RCE) - Unauthenticated attackers could execute remote commands via deserialization of untrusted data.
Patterns: Repeated unauthenticated remote code execution vulnerabilities.; File upload vulnerabilities leading to arbitrary code execution.
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-03-20 | CVE-2025-54068 | high | Laravel Livewire allows unauthenticated attackers to execute remote commands via code injection. |
| 2023-09-18 | CVE-2021-3129 | critical | Unauthenticated attackers could execute arbitrary code via a file upload vulnerability in Laravel Ignition. |
| 2024-01-16 | CVE-2018-15133 | high | Laravel Framework's CVE-2018-15133 allows remote code execution if an attacker obtains the APP_KEY environment variable. |
DOSSIER SOURCES
- laravel CVE Vulnerabilities & Metrics · cve.akaoma.com
- Composer/Laravel/Framework | GitLab Advisory Database (GLAD) · advisories.gitlab.com
- The ORM Didn't Save You: SQL Injection Through Raw Query Builder ... · jcadima.dev
Open questions: How has Laravel addressed these vulnerabilities? · What is the current state of security in Laravel's codebase?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-27 03:42:21.022332+00:00