<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Laravel</title>
  <link>https://cvedaily.com/pages/tags/laravel.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/laravel.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Laravel</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2022-31114 – backpack/crud provides Create, Read, Update &amp; Delete (CRUD) functions for Backpa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31114</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31114</strong></p>
  <p>backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.69, and 4.0.63 are vulnerable to cross-site scripting. An attacker could conduct a targeted phishing campaign, in order to trick users or admins into clicking a malicious link, which under very specif…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48811 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48811</guid>
    <pubDate>Fri, 29 May 2026 20:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48811</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete an internal note (private thread) from any conversation, even after that user's access to the mailbox containing the conversation has been revoked. The ThreadPolicy::delete authorization policy does not verify mailbox membership, so a former…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48810 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48810</guid>
    <pubDate>Fri, 29 May 2026 20:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48810</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the same missing mailbox membership check was found in the sibling ThreadPolicy::edit method. A user with the PERM_EDIT_CONVERSATIONS permission who created a message or internal note in Mailbox A can rewrite that thread's bod…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48557 – Spatie Laravel Media Library before version 11.23.0 contains a file upload restr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48557</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48557</strong></p>
  <p>Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypass the blocklist, with pathinfo() preserving inner .php stems in saved filenames. The blocklist also omits executable extensions including .php6, .shtml,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48555 – Spatie Laravel Media Library before version 11.23.0 contains a server-side reque...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48555</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48555</strong></p>
  <p>Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47123 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47123</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47123</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / References headers. The notification reply path (notify-{thread_id}-{user_id}-...) extracts thread_id and user_id directly from the Message-ID without HMA…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45294 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45294</guid>
    <pubDate>Fri, 29 May 2026 20:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45294</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted email address belongs to an existing user account, allowing unauthenticated attackers to enumerate valid helpdesk agent email addresses. This vulnerability is fixed in 1.8.219.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45660 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45660</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45660</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed using an IP representation that wasn't normalized before the public-IP check. An unauthenticated user could cause the server to make HTTP requests to internal addresses — including loopback, private network, and cloud metadata endpoints. This…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44306 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44306</guid>
    <pubDate>Tue, 12 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44306</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot password forms hinted at whether an account existed for a given email address. An unauthenticated attacker could use this to enumerate valid users, which can aid in follow-up credential-based attacks. This vulnerability is fixed in 5.73.21 and 6.15.0.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-204</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44262 – Scramble generates API documentation for Laravel project. From 0.13.2 to before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44262</guid>
    <pubDate>Tue, 12 May 2026 22:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44262</strong></p>
  <p>Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code in the application context. This vulnerability is fixed in 0.13.22.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41524 – Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41524</guid>
    <pubDate>Fri, 08 May 2026 15:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41524</strong></p>
  <p>Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is permanently stored and executed in every visitor's browser upon page load. This issue has…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41906 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41906</guid>
    <pubDate>Thu, 07 May 2026 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41906</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope customers through the mailbox-filtered search endpoint, but the backend conversation_change_customer action accepts any supplied customer_email. A low-privileged agent can forge a request and bind a visible conversation to a hidden cus…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41905 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41905</guid>
    <pubDate>Thu, 07 May 2026 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41905</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via curlGetLastRedirectedUrl() but then re-validates the original URL instead of the final redirect destination. An attacker who can supply any URL that passes the initial host check can redirect FreeScout to interna…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41904 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41904</guid>
    <pubDate>Thu, 07 May 2026 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41904</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS payload in the mailbox auto-reply message. The payload is rendered unescaped in the auto-reply email sent to every customer who contacts the mailbox. Email clients do not enforce CSP, so the payload executes in the customer's webmail…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41903 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41903</guid>
    <pubDate>Thu, 07 May 2026 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41903</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding the PERM_EDIT_USERS permission (intended for general user-profile editing) can read and modify the notification subscriptions of any other user, including admins, by sending a single POST request. This is a sibling of CVE-2025-48472's notification authorization bypass — the…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41902 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41902</guid>
    <pubDate>Thu, 07 May 2026 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41902</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new user's password. The endpoint performs no expiration check — the hash remains valid indefinitely until consumed. Combined with realistic hash-leakage scenarios (forwarded invite emails, HTTP referrer to…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-7110 – A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7110</guid>
    <pubDate>Mon, 27 Apr 2026 10:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-7110</strong></p>
  <p>A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7109 – A vulnerability was detected in code-projects Invoice System in Laravel 1.0. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7109</guid>
    <pubDate>Mon, 27 Apr 2026 10:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7109</strong></p>
  <p>A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7108 – A security vulnerability has been detected in code-projects Invoice System in La...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7108</guid>
    <pubDate>Mon, 27 Apr 2026 09:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7108</strong></p>
  <p>A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7107 – A weakness has been identified in code-projects Invoice System in Laravel 1.0. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7107</guid>
    <pubDate>Mon, 27 Apr 2026 09:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7107</strong></p>
  <p>A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7093 – A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7093</guid>
    <pubDate>Mon, 27 Apr 2026 07:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7093</strong></p>
  <p>A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7092 – A vulnerability has been found in code-projects Invoice System in Laravel 1.0. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7092</guid>
    <pubDate>Mon, 27 Apr 2026 07:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7092</strong></p>
  <p>A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile Handler. Such manipulation of the argument ID leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7091 – A flaw has been found in code-projects Invoice System in Laravel 1.0. This impac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7091</guid>
    <pubDate>Mon, 27 Apr 2026 07:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7091</strong></p>
  <p>A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User Management Handler. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41175 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41175</guid>
    <pubDate>Wed, 22 Apr 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41175</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requires authentication with minimal permissions in order to exploit. e.g. "view entries" permission to…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31843 – The goodoneuz/pay-uz Laravel package (&lt;= 2.2.24) contains a critical vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31843</guid>
    <pubDate>Thu, 16 Apr 2026 13:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31843</strong></p>
  <p>The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any() without authentication middleware, enabling remote access without credentials. User-controlled input is directly written into executable PHP files…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39976 – Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39976</guid>
    <pubDate>Thu, 09 Apr 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39976</strong></p>
  <p>Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this value to retrieveById() without validating it's actually a user identifier, potentially resolving an unre…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39384 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39384</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39384</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parameter into account when merging customers. This vulnerability is fixed in 1.8.212.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35584 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35584</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35584</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation_id}/{thread_id} does not require authentication and does not validate whether the given thread_id belongs to the given conversation_id. This allows any unauthenticated attacker to mark any thread as read by passing arbitrary IDs, enumerate valid thread I…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25673 – UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25673</guid>
    <pubDate>Sun, 05 Apr 2026 21:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25673</strong></p>
  <p>UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-5370 – A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5370</guid>
    <pubDate>Thu, 02 Apr 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-5370</strong></p>
  <p>A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch i…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34456 – Reviactyl is an open-source game server management panel built using Laravel, Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34456</guid>
    <pubDate>Wed, 01 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34456</strong></p>
  <p>Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email addresses. An attacker could create or control a social account (e.g., Google, GitHub, Discord) using…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34443 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34443</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34443</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the function always returns false without checking any CIDR ranges. The entire 10.0.0.0/8 and 172.16.0.0/12 private ranges are unprotected. This issue has been…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34442 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34442</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34442</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External Resource Loading and Open Redirect behavior. When the application constructs links and assets using the…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33887 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33887</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33887</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the required collection permissions. This bypasses the authorization checks that the main entry controllers enforce, exposing entry field values and bluepri…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33886 – Statamic is a Laravel and Git powered content management system (CMS). Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33886</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33886</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33885 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33885</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33885</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions and authentication flows. This has been fixed in 5.73.16 and 6.7.2.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33884 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33884</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33884</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This has been fixed in 5.73.16 and 6.7.2.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33883 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33883</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33883</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could render user-input directly into HTML without escaping, allowing an attacker to craft a URL that executes arbitrary JavaScript in the victim's browser. This has been fixed in 5.73.16 and 6.7.2.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33882 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33882</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33882</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be manipulated to return augmented data from arbitrary fieldtypes. With the users fieldtype specifically, an authenticated control panel user could retrieve sensitive user data including email addresses, encrypted passkey data, and encrypted two-factor au…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33687 – Sharp is a content management framework built for Laravel as a package. Versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33687</guid>
    <pubDate>Thu, 26 Mar 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33687</strong></p>
  <p>Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allows authenticated users to bypass all file type restrictions. The upload endpoint within the `ApiFormUploadController` accepts a client-controlled `validation_rule` parameter. This parameter is directly passed into the Laravel validator witho…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33686 – Sharp is a content management framework built for Laravel as a package. Versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33686</guid>
    <pubDate>Thu, 26 Mar 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33686</strong></p>
  <p>Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability  in the FileUtil class. The application fails to sanitize file extensions properly, allowing path separators to be passed into the storage layer. In `src/Utils/FileUtil.php`, the `FileUtil::explodeExtension()` function extracts a file's extension by splitting the fi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33742 – Invoice Ninja is a source-available invoice, quote, project and time-tracking ap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33742</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33742</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33742</strong></p>
  <p>Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 allow raw HTML via Markdown rendering, enabling stored XSS. The Markdown parser output was not sanitized with `purify::clean()` before being included in invoice templates. This is fixed in v5.13.4 by the vendor by adding `purify::clean()` to sanitize…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33742">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33628 – Invoice Ninja is a source-available invoice, quote, project and time-tracking ap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33628</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33628</strong></p>
  <p>Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja v5.13.0 bypass the XSS denylist filter, allowing stored XSS payloads to execute when invoices are rendered in the PDF preview or client portal. The line item description field was not passed through `purify::clean()` before rendering. This is fixed…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4809 – plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4809</guid>
    <pubDate>Thu, 26 Mar 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4809</strong></p>
  <p>plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload. If the uploaded file is stored…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33177 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33177</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33177</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileged Control Panel users could create taxonomy terms by submitting requests to the field action processing endpoint with attacker-controlled field definitions. This bypasses the authorization checks enforced on the standard taxonomy term creation endpoint. This has been fixed in 5…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33172 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33172</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33172</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to bypass SVG sanitization and inject malicious JavaScript that executes when the asset is viewed. This has been fixed in 5.73.14 and 6.7.0.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33171 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33171</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33171</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticated Control Panel users could read arbitrary `.json`, `.yaml`, and `.csv` files from the server by manipulating the file dictionary's `filename` configuration parameter in the fieldtype's endpoint. This has been fixed in 5.73.14 and 6.7.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33080 – Filament is a collection of full-stack components for accelerated Laravel develo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33080</guid>
    <pubDate>Fri, 20 Mar 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33080</strong></p>
  <p>Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two Filament Table summarizers (Range, Values) that render raw database values without escaping HTML. If there is a lack of validation for the data in the columns that use these summarizers, an attacker could plant malicious HTML / JavaScript and achieve…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32754 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32754</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32754</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming email bodies are stored in the database without sanitization and rendered unescaped in outgoing email notifications using Blade's raw output syntax {!! $thread->body !!}. An unau…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32753 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32753</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32753</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An extension of .png with content type of image/svg+xml is allowed, and a fallback mechanism on invalid XML leads to unsafe sanitization. The applicatio…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-32752 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32752</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-32752</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy::edit() method contains a broken access control vulnerability that allows any authenticated user (regardless of role or mailbox access) to read and modify all customer-created thread messages across all mailboxes. This flaw enables silent modification of customer mess…</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32612 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32612</guid>
    <pubDate>Fri, 13 Mar 2026 19:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32612</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a higher-privileged user impersonates their account. This has been fixed in 6.6.2.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27591 – Winter is a free, open-source content management system (CMS) based on the Larav...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27591</guid>
    <pubDate>Wed, 11 Mar 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27591</strong></p>
  <p>Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifying the roles / permissions assigned to their account through specially crafted requests to the backend while logged in. To actively exploit this secu…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28289 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28289</guid>
    <pubDate>Tue, 03 Mar 2026 23:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28289</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnera…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28426 – Statmatic is a Laravel and Git powered content management system (CMS). Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28426</guid>
    <pubDate>Fri, 27 Feb 2026 23:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28426</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This has been fixed in 5.73.11 and 6.4.0.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28425 – Statmatic is a Laravel and Git powered content management system (CMS). Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28425</guid>
    <pubDate>Fri, 27 Feb 2026 23:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28425</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. That can lead to full compromise of the application, including access to sensitive configuration, modification or exfiltration of data, and pot…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28424 – Statmatic is a Laravel and Git powered content management system (CMS). Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28424</guid>
    <pubDate>Fri, 27 Feb 2026 23:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28424</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28423 – Statmatic is a Laravel and Git powered content management system (CMS). Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28423</guid>
    <pubDate>Fri, 27 Feb 2026 23:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28423</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the image proxy can be abused by an unauthenticated user to make the server send HTTP requests to arbitrary URLs—either via the URL directly or via the watermark feature. That can allow access to internal se…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27939 – Statmatic is a Laravel and Git powered content management system (CMS). Starting...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27939</guid>
    <pubDate>Fri, 27 Feb 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27939</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. T…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27637 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27637</guid>
    <pubDate>Wed, 25 Feb 2026 04:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27637</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication token computed as `MD5(user_id + created_at + APP_KEY)`. This token is static (never expires/rotates), and if an attacker obtains the `APP_KEY` — a well-documented and common exposure vector in Laravel applications — they…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27636 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27636</guid>
    <pubDate>Wed, 25 Feb 2026 04:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27636</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Helper.php` does not include `.htaccess` or `.user.ini` files. On Apache servers with `AllowOverride All` (a common configuration), an authenticated user can upload a `.htaccess` file to redefine how files are processed, enabling Remote…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27621 – TypiCMS is a multilingual content management system based on the Laravel framewo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27621</guid>
    <pubDate>Wed, 25 Feb 2026 03:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27621</strong></p>
  <p>TypiCMS is a multilingual content management system based on the Laravel framework. A Stored Cross-Site Scripting (XSS) vulnerability exists in the file upload module of TypiCMS prior to version 16.1.7. The application allows users with file upload permissions to upload SVG files. While there is a MIME type validation, the content of the SVG file is not sanitized. An attacker can upload a special…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27593 – Statmatic is a Laravel and Git powered content management system (CMS). Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27593</guid>
    <pubDate>Tue, 24 Feb 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27593</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email address of a valid account on the site, and the actual user must blindly click the link in their email even though they…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27196 – Statmatic is a Laravel and Git powered content management system (CMS). Versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27196</guid>
    <pubDate>Sat, 21 Feb 2026 05:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27196</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated users with field management permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This issue has been fixed in 6.3.2 and 5.73.9.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25759 – Statmatic is a Laravel and Git powered content management system (CMS). From 6.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25759</guid>
    <pubDate>Wed, 11 Feb 2026 21:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25759</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. Malicious user must have an account with control panel access and content creation permissions. This vulnera…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25633 – Statamic is a, Laravel + Git powered CMS designed for building websites. Prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25633</guid>
    <pubDate>Wed, 11 Feb 2026 21:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25633</strong></p>
  <p>Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-22254 – Winter is a free, open-source content management system (CMS) based on the Larav...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22254</guid>
    <pubDate>Fri, 06 Feb 2026 20:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-22254</strong></p>
  <p>Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to upload SVGs without automatic sanitization. To actively exploit this security issue, an attacker would need access to the Backend with a user account with the following permission: cms.manage_assets. Th…</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-70841 – Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70841</guid>
    <pubDate>Tue, 03 Feb 2026 18:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-70841</strong></p>
  <p>Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encryption key (APP_KEY), database credentials, SMTP/SendGrid API credentials, and internal configuration parameters, enabling complete system compromise including…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25129 – PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25129</guid>
    <pubDate>Fri, 30 Jan 2026 21:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25129</strong></p>
  <p>PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim's cont…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-36950 – Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36950</guid>
    <pubDate>Tue, 27 Jan 2026 16:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-36950</strong></p>
  <p>Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23524 – Laravel Reverb provides a real-time WebSocket communication backend for Laravel ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23524</guid>
    <pubDate>Wed, 21 Jan 2026 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23524</strong></p>
  <p>Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into PHP’s unserialize() function without restricting which classes can be instantiated, which leaves users vulnerable to Remote Code Execution. The exploitability of this vulnerability is increased because Redis servers are…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14894 – Livewire Filemanager, commonly used in Laravel applications, contains LivewireFi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14894</guid>
    <pubDate>Fri, 16 Jan 2026 13:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14894</strong></p>
  <p>Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47756 – Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47756</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47756</strong></p>
  <p>Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the symlinked valet command to execute arbitrary code with root permissions without additional authentication.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21451 – Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21451</guid>
    <pubDate>Fri, 02 Jan 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21451</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `<script>` tags, the filtering can be bypassed by manipulating the raw HTTP POST request before submission. As a result, arbitrary JavaScript can be stored in the CMS conten…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-21450 – Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21450</guid>
    <pubDate>Fri, 02 Jan 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-21450</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21449 – Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21449</guid>
    <pubDate>Fri, 02 Jan 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21449</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-21448 – Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21448</guid>
    <pubDate>Fri, 02 Jan 2026 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-21448</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.3.10 contains a patch.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21447 – Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21447</guid>
    <pubDate>Fri, 02 Jan 2026 21:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21447</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to their own shopping cart by manipulating the order ID parameter. This exposes sensitive purchase information and enables potential fraud. Version 2.3.10…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-21446 – Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 bra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21446</guid>
    <pubDate>Fri, 02 Jan 2026 20:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-21446</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exploitable without any authentication. An attacker can bypass the Ib installer entirely by calling the API endpoints directly. This allows any unauthen…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68129 – Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68129</guid>
    <pubDate>Wed, 17 Dec 2025 22:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68129</strong></p>
  <p>Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they use Auth0-PHP SDK versions between v8.0.0 and v8.17.0, or applications using the following SDKs that…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67507 – Filament is a collection of full-stack components for accelerated Laravel develo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67507</guid>
    <pubDate>Wed, 10 Dec 2025 01:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67507</strong></p>
  <p>Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. This issue is fixed in version 4.3…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66509 – LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66509</guid>
    <pubDate>Thu, 04 Dec 2025 22:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66509</strong></p>
  <p>LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically execute the ServiceProvider::boot() method, enabling arbitrary PHP code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-65346 – alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65346</guid>
    <pubDate>Thu, 04 Dec 2025 15:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-65346</strong></p>
  <p>alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-65345 – alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65345</guid>
    <pubDate>Wed, 03 Dec 2025 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-65345</strong></p>
  <p>alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path validation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13121 – A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13121</guid>
    <pubDate>Thu, 13 Nov 2025 17:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13121</strong></p>
  <p>A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/app/Http/Controllers/Front/StoreController.php of the component API Endpoint. Such manipulation of the argument lng/lat leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63307 – alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63307</guid>
    <pubDate>Thu, 06 Nov 2025 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63307</strong></p>
  <p>alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64112 – Statmatic is a Laravel and Git powered content management system (CMS). Stored X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64112</guid>
    <pubDate>Thu, 30 Oct 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64112</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fixed in 5.22.1.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62798 – Sharp is a content management framework built for Laravel as a package. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62798</guid>
    <pubDate>Tue, 28 Oct 2025 21:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62798</strong></p>
  <p>Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }} were evaluated by Vue. This allowed attackers to inject arbitrary JavaScript or HTML that executes in the browser when t…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56399 – alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56399</guid>
    <pubDate>Tue, 28 Oct 2025 16:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56399</strong></p>
  <p>alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '.png` extension containing PHP code can be uploaded via the file manager interface. Although the upload appears to fail client-side validation, the file is still saved on the server. The attacker can then use the rename API to change…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62523 – PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62523</guid>
    <pubDate>Mon, 27 Oct 2025 21:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62523</strong></p>
  <p>PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing (CORS) misconfiguration in its middleware: it reflects the Origin request header back in the Access-Control-Allow-Origin response header without proper validation or a whitelist, while Access-Control-Allow-Credentials is set to true. This behavior coul…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62418 – Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the Tin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62418</guid>
    <pubDate>Thu, 16 Oct 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62418</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted SVG file containing embedded JavaScript. When viewed, the malicious code executes in the context of the admin/user’s browser. This vulnerability is fixed in 2.3.8.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62417 – Bagisto is an open source laravel eCommerce platform. When product data that beg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62417</guid>
    <pubDate>Thu, 16 Oct 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62417</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet will interpret that cell as a formula. This allows an attacker to supply a CSV field (e.g., product name) that contains a formula which may be eval…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62416 – Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62416</guid>
    <pubDate>Thu, 16 Oct 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62416</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with product creation privileges to inject arbitrary template expressions that are evaluated by the backend — potentially leading t…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62415 – Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the Tin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62415</guid>
    <pubDate>Thu, 16 Oct 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62415</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted HTML file containing embedded JavaScript. When viewed, the malicious code executes in the context of the admin/user’s browser. This vulnerability is fixed in 2.3.8.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62414 – Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62414</guid>
    <pubDate>Thu, 16 Oct 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62414</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel) is vulnerable to Cross-Site Scripting (XSS). An attacker with access to the admin create-customer form can inject malicious JavaScript payloads into certain input fields. These payloads may later execute in the context of an admin’s browser or another user viewing the cu…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-11443 – A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11443</guid>
    <pubDate>Wed, 08 Oct 2025 08:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-11443</strong></p>
  <p>A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/password/email of the component Forgotten Password Handler. This manipulation causes information exposure through discrepancy. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The exploit has…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-58769 – auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58769</guid>
    <pubDate>Wed, 01 Oct 2025 20:18:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-58769</strong></p>
  <p>auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications built with the SDK does not validate the file-path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs. The vulnerability affects any application that either directly uses the Auth0-PHP SDK (version…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34216 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34216</guid>
    <pubDate>Mon, 29 Sep 2025 21:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34216</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passwords. The same endpoints also disclose the Laravel APP_KEY used for cryptographic signing. Because the APP_KEY is required to generate valid sig…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34206 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34206</guid>
    <pubDate>Fri, 19 Sep 2025 19:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34206</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers with overly-permissive filesystem permissions. Files such as secrets.env, GPG-encrypted blobs in .secrets, MySQL client keys, and application session files are accessible from multiple containers.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34203 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34203</guid>
    <pubDate>Fri, 19 Sep 2025 19:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34203</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior to 20.0.2614 (VA and SaaS deployments) contain multiple Docker containers that include outdated, end-of-life, unsupported, or otherwise vulnerable third-party components (examples: Nginx 1.17.x, OpenSSL 1.1.1d, various EOL Alpine/Debian/Ubuntu base images, and EOL Laravel/PHP lib…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34203">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
