← Vulnerability feed

Vulnerability record · CVE-2024-13919 · published 10 March 2025

CVE-2024-13919: Laravel framework cross-site scripting vulnerability

Laravel · Framework

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.

6.1 CVSS 3.1 Medium EPSS 0.52% · top 58.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-13919 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43617Laravel framework unrestricted file upload vulnerabilityLaravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAtt…EPSS 20%8.8CVE-2020-19316Laravel framework os command injection vulnerabilityOS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.EPSS 2.5%8.8CVE-2018-6330Laravel framework sql injection vulnerabilityLaravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.EPSS 1.6%8.7CVE-2024-52301Laravel framework argument injection alters request environmentLaravel mishandles the register_argc_argv PHP directive: when that directive is on, a crafted query string on any URL can inject argv values that cha…EPSS 45%analysed6.9CVE-2025-27515Laravel framework vulnerabilityLaravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious …EPSS 0.73%6.1CVE-2024-13918Laravel framework cross-site scripting vulnerabilityThe Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request pa…EPSS 0.59%6.1CVE-2021-43808Laravel framework cross-site scripting vulnerabilityLaravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerabi…EPSS 0.80%5.3CVE-2022-40482Laravel framework observable discrepancy vulnerabilityThe authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks wi…EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2024-13919), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.