Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 12 SEP 2026

Laravel · AUTOMATIC DISCOVERY

Laravel 13

Laravel is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

Laravel is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductLaravel
Release13
End of Active supportSeptember 2027
End of SupportMarch 2028
Date precisionQuarter

Known exploited vulnerabilities

Catalogue updated 11 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2025-54068Added 20 Mar 2026

Laravel Livewire Code Injection Vulnerability

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

Laravel · LivewireRansomware use: Unknown

CISA entry
CVE-2018-15133Added 16 Jan 2024

Laravel Deserialization of Untrusted Data Vulnerability

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).

Laravel · Laravel FrameworkRansomware use: Unknown

CISA entry
CVE-2021-3129Added 18 Sep 2023

Laravel Ignition File Upload Vulnerability

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

Laravel · IgnitionRansomware use: Known

CISA entry

Package vulnerability advisories

Checked 10 Sep 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2026-48019High severity

Laravel Framework: CRLF injection in default email rule

pkg:composer/laravel/frameworkFixed: 13.10.0, 12.60.0

OSV record
CVE-2025-27515Medium severity

Laravel has a File Validation Bypass

pkg:composer/laravel/frameworkFixed: 12.1.1, 11.44.1, 10.48.29

OSV record
CVE-2021-43808Medium severity

Laravel Framework XSS in Blade templating engine

pkg:composer/laravel/frameworkFixed: 6.20.42, 7.30.6, 8.75.0

OSV record
CVE-2024-13919Medium severity

Laravel framework susceptible to reflected cross-site scripting

pkg:composer/laravel/frameworkFixed: 11.36.0

OSV record
CVE-2024-13918Medium severity

Laravel framework susceptible to reflected cross-site scripting

pkg:composer/laravel/frameworkFixed: 11.36.0

OSV record

Source evidence

PRIMARYManual

Laravel official lifecycle source

Version | PHP (*) | Release | Bug Fixes Until | Security Fixes Until | 13 | 8.3 - 8.5 | Q1 2026 | Q3 2027 | Q1 2028

Publisher identity used by product-specific official-source collectors.

First collected 2 Sep 2026 · Last collected 12 Sep 2026 · Review state accepted

Open official vendor source