hacktribunebeta
IncidentsAlertsNewsletterPricingAbout
Live feedSign in with GitHub
Home / Frameworks / Laravel

Laravel security incidents

Recent advisories touching Laravel apps — searchable, enriched with exploit probability and affected versions.

CRITICALExploitedunknown

Laravel Livewire Code Injection Vulnerability

https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 ; https://github.com/livewire/livewire/commit/ef04be759da41b14d2d129e670533180a44987dc ; https://nvd.nist.gov/vuln/detail/CVE-2025-54068

4 months agoEPSS 95%
CRITICALExploitedunknown

Laravel Deserialization of Untrusted Data Vulnerability

https://laravel.com/docs/5.6/upgrade#upgrade-5.6.30; https://nvd.nist.gov/vuln/detail/CVE-2018-15133

2 years agoEPSS 77%
CRITICALExploitedunknown

Laravel Ignition File Upload Vulnerability

https://github.com/facade/ignition/releases/tag/2.5.2; https://nvd.nist.gov/vuln/detail/CVE-2021-3129

2 years agoEPSS 100%

Tooling for Laravel

Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

hacktribune
Developer security signal for the stack you actually run.
IncidentsTopicsEcosystemsFrameworksPricingAboutRSS
Incident data: OSV · CISA KEV · EPSS (FIRST)