Vulnerabilities > Laravel > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-25 CVE-2022-40482 Information Exposure Through Discrepancy vulnerability in Laravel Framework
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing.
network
low complexity
laravel CWE-203
5.3
2021-12-08 CVE-2021-43808 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Laravel Framework
Laravel is a web application framework.
network
low complexity
laravel CWE-327
6.1
2021-01-19 CVE-2021-21263 SQL Injection vulnerability in Laravel
Laravel is a web application framework.
network
low complexity
laravel CWE-89
5.3
2017-09-28 CVE-2017-14775 Information Exposure vulnerability in Laravel
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
network
high complexity
laravel CWE-200
5.9
2017-05-29 CVE-2017-9303 Improper Input Validation vulnerability in Laravel 5.4.0
Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.
network
low complexity
laravel CWE-20
6.1