Real-time CVE monitoring

CVE alerts for
Laravel

CVEye scans every new CVE and notifies your team the moment Laravel is affected — before attackers can exploit it.

Monitor Laravel free →No credit card · 7-day trial

Recent Laravel CVEs

  • CVE-2026-53932HIGHCVSS 8.0

    laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.

  • Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an authenticated user by directing them to a crafted page. Laravel's VerifyCsrfToken middleware enforces CSRF tokens only on POST, PUT, PATCH, and DELETE requests; the Route::get declaration leaves this state-changing action unprotected. Session cookies configured with SameSite=Lax are automatically included in top-level cross-site navigation, so a single link click triggers OrderConfirmController::confirm() and transitions the target order from pending to confirmed without user authorization. Because order numbers are sequential integers, an attacker can enumerate and confirm all existing orders in a single automated sweep.

Never miss a Laravel vulnerability

CVEye monitors Laravel and your entire stack 24/7, sending instant alerts via email, Slack, Discord, or webhook the moment a new CVE is published.

7-day free trial · No credit card required

Also monitor