Laravel Livewire vulnerabilities
4 known vulnerabilities affecting laravel/livewire.
Total CVEs
4
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-54068P1CRITICALCVSS 9.8KEVPoC≥ 3.0.0, < 3.6.42025-07-17
CVE-2025-54068 [CRITICAL] CWE-94 CVE-2025-54068: Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnera
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major v
nvd
CVE-2024-47823P3CRITICALCVSS 9.8fixed in 2.12.7≥ 3.0.0, < 3.5.22024-10-08
CVE-2024-47823 [CRITICAL] CWE-20 CVE-2024-47823: Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving
Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An attacker can therefore bypass the vali
nvd
CVE-2024-22859P3HIGHCVSS 8.8fixed in 3.0.42024-02-01
CVE-2024-22859 [HIGH] CWE-352 CVE-2024-22859: Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers t
Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d88731 commit fixes a usability problem (HTTP 419 status codes for legitimate client activity), not a security problem.
nvd
CVE-2024-21504P4MEDIUMCVSS 6.1≥ 3.3.5, ≤ 3.4.92024-03-19
CVE-2024-21504 [MEDIUM] CWE-79 CVE-2024-21504: Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site S
Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HTML code in the context of the user's browser session by crafting a malicious link and convincing the user to click on it.
nvd