CVE-2025-54068 is a code injection vulnerability in Laravel Livewire that CISA has placed in the Known Exploited Vulnerabilities catalog. Because it is listed in KEV, defenders should treat it as an active-risk issue and follow the vendor-linked remediation guidance without delay.
CVE-2018-15133 is a Laravel Framework deserialization of untrusted data vulnerability that CISA placed in the Known Exploited Vulnerabilities (KEV) catalog on 2024-01-16. Because KEV inclusion indicates known exploitation, organizations using Laravel Framework should treat this as a high-priority remediation item and follow the vendor’s mitigation guidance. If mitigations are not available, CISA’s guidanc [truncated]
CVE-2021-3129 is a Laravel Ignition file upload vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it has been observed in real-world abuse and is associated with known ransomware campaign use, organizations should treat affected Ignition deployments as high priority for review and remediation. The supplied official sources do not provide deeper technical detail, so the [truncated]