CVE-2025-27515
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
05/03/2025
Last modified:
26/08/2025
Description
Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:* | 11.44.1 (excluding) | |
| cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:* | 12.0.0 (including) | 12.1.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



