← Vulnerability feed

Vulnerability record · CVE-2021-43808 · published 8 December 2021

CVE-2021-43808: Laravel framework cross-site scripting vulnerability

Laravel · Framework

Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user taken to another location in their browser due to XSS. This is due to the user being able to guess the parent placeholder SHA-1 hash by trying common names of sections. If the parent template contains an exploitable HTML structure an XSS vulnerability can be exposed. This vulnerability has been patched in versions 8.75.0, 7.30.6, and 6.20.42 by determining the parent placeholder at runtime and using a random hash that is unique to each request.

6.1 CVSS 3.1 Medium EPSS 0.80% · top 45.2% CWE-79 · Cross-site scriptingCWE-327 · Broken cryptographic algorithm
6.1CVSS 3.1 base score, v2 4.3
0.80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user taken to another location in their browser due to XSS. This is due to the user being able to guess the parent placeholder SHA-1 hash by trying common names of sections. If the parent template contains an exploitable HTML structure an XSS vulnerability can be exposed. This vulnerability has been patched in versions 8.75.0, 7.30.6, and 6.20.42 by determining the parent placeholder at runtime and using a random hash that is unique to each request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43808 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43617Laravel framework unrestricted file upload vulnerabilityLaravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAtt…EPSS 20%8.8CVE-2020-19316Laravel framework os command injection vulnerabilityOS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.EPSS 2.5%8.8CVE-2018-6330Laravel framework sql injection vulnerabilityLaravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.EPSS 1.6%8.7CVE-2024-52301Laravel framework argument injection alters request environmentLaravel mishandles the register_argc_argv PHP directive: when that directive is on, a crafted query string on any URL can inject argv values that cha…EPSS 45%analysed6.9CVE-2025-27515Laravel framework vulnerabilityLaravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious …EPSS 0.73%6.1CVE-2024-13919Laravel framework cross-site scripting vulnerabilityThe Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route para…EPSS 0.52%6.1CVE-2024-13918Laravel framework cross-site scripting vulnerabilityThe Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request pa…EPSS 0.59%5.3CVE-2022-40482Laravel framework observable discrepancy vulnerabilityThe authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks wi…EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2021-43808), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.