laradashboard

14 known vulnerabilities in laradashboard, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-105130 CVSS 6.3 medium LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated…
  • CVE-2026-105129 CVSS 7.1 high LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view…
  • CVE-2026-105128 CVSS 5.3 medium LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an…
  • CVE-2026-105127 CVSS 6.9 medium LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests…
  • CVE-2026-105126 CVSS 8.6 high LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to…
  • CVE-2026-105125 CVSS 6.3 medium LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by…
  • CVE-2026-90933 CVSS 7.1 high laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any…
  • CVE-2026-90932 CVSS 8.6 high LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling…
  • CVE-2026-90931 CVSS 5.1 medium LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only…
  • CVE-2026-87821 CVSS 7.1 high Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint…
  • CVE-2026-86438 CVSS 8.6 high Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin…
  • CVE-2026-86437 CVSS 8.6 high Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission…
  • CVE-2026-86436 CVSS 5.3 medium Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated…
  • CVE-2026-86184 CVSS 9.3 critical Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated…