laravel/framework Security Advisories for v7.8.0 (7)
-
[HIGH] Improper Input Validation in Laravel
PKSA-7ywf-hktb-jkn9 CVE-2020-24941 GHSA-w68r-5p45-5rqp
Affected version: >=7.0.0,<7.24.0|<6.18.35
Reported by:
GitHub -
[MEDIUM] SQL Server LIMIT / OFFSET SQL Injection
PKSA-ckwp-rt7t-c46m GHSA-7852-w36x-6mf6
Affected version: >=6.0.0,<6.20.26|>=7.0.0,<7.30.5|>=8.0.0,<8.40.0
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] Unexpected bindings in QueryBuilder
PKSA-4npr-btr6-zhny GHSA-6jvx-8ch9-j2jr
Affected version: >=6.0.0,<6.20.14|>=7.0.0,<7.30.4|>=8.0.0,<8.24.0
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] Possible cross-site scripting (XSS) vulnerability in the Blade templating engine
PKSA-njrm-6dtg-m2pc CVE-2021-43808 GHSA-66hf-2p6w-jqfw
Affected version: <6.20.42|>=7.0.0,<7.30.6|>=8.0.0,<8.75.0
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[CRITICAL] Guard bypass in Eloquent models
PKSA-vhvj-tvg4-96jj GHSA-qm5c-m76r-2hfr
Affected version: >=5.5.0,<=5.5.49|>=6.0.0,<6.18.34|>=7.0.0,<7.23.2
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] RCE vulnerability in "cookie" session driver
PKSA-nrj3-r2wg-yt8b GHSA-vr95-p7q6-8m9q
Affected version: >=4.1.0,<=4.1.99999|>=4.2.0,<=4.2.99999|>=5.0.0,<=5.0.99999|>=5.1.0,<=5.1.99999|>=5.2.0,<=5.2.99999|>=5.3.0,<=5.3.99999|>=5.4.0,<=5.4.99999|>=5.5.0,<=5.5.49|>=5.6.0,<=5.6.99999|>=5.7.0,<=5.7.99999|>=5.8.0,<=5.8.99999|>=6.0.0,<6.18.31|>=7.0.0,<7.22.4
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] Unexpected bindings in QueryBuilder
PKSA-985r-hryy-555b CVE-2021-21263 GHSA-3p32-j457-pg5x
Affected version: >=6.0.0,<6.20.11|>=7.0.0,<7.30.2|>=8.0.0,<8.22.1
Reported by:
GitHub, FriendsOfPHP/security-advisories