Vulnerabilities (CVE)

Filtered by vendor Alexusmai Subscribe
Filtered by product Laravel File Manager
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-63307 1 Alexusmai 1 Laravel File Manager 2025-12-08 N/A 8.1 HIGH
alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.