Vulnerabilities > Laravel > Framework > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-03-10 CVE-2024-13918 Cross-site Scripting vulnerability in Laravel Framework
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.
network
low complexity
laravel CWE-79
6.1
2025-03-10 CVE-2024-13919 Cross-site Scripting vulnerability in Laravel Framework
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.
network
low complexity
laravel CWE-79
6.1
2023-04-25 CVE-2022-40482 Information Exposure Through Discrepancy vulnerability in Laravel Framework
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing.
network
low complexity
laravel CWE-203
5.3
2021-12-08 CVE-2021-43808 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Laravel Framework
Laravel is a web application framework.
network
low complexity
laravel CWE-327
6.1