CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 2 findings are in the CISA KEV catalog (0 in production dependencies):
| Package | Your version | CVE | Fixed in | Exploit context |
|---|---|---|---|---|
| phpunit/phpunit dev | ^10.5.35 || ^11.5.15 || ^12.5.8 || ^13.3.0 (unpinned) | CVE-2017-9841 | 4.8.28 | KEV listed 2022-02-15 |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 (unpinned) | CVE-2018-15133 | 5.6.30 | KEV listed 2024-01-16 |
⚠ No lockfile — SBOM is not reproducible
This scan is based on a manifest (composer.json), not a lockfile. 17 of 17 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.
All findings (34)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2024-52301 | HIGH | 44.8% | 6.20.45 | Laravel environment manipulation via query string |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2020-19316 | HIGH | 2.5% | 5.8.17 | OS Command Injection in Laravel Framework |
| illuminate/database | ^11.44.2 || ^12.4.1 || ^13 | CVE-2021-21263 | HIGH | 1.6% | 7.30.3 | Query Binding Exploitation |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2021-21263 | HIGH | 1.6% | 8.22.1 | Query Binding Exploitation |
| illuminate/database | ^11.44.2 || ^12.4.1 || ^13 | CVE-2020-24940 | HIGH | 1.2% | 6.18.34 | Guard bypass in Eloquent models affecting Laravel illuminate database component |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2017-14775 | MODERATE | 1.2% | 5.5.10 | Laravel Sensitive Data Exposure |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2020-24941 | HIGH | 1.1% | 6.18.35 | Improper Input Validation in Laravel |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2017-9303 | MODERATE | 1.0% | 5.4.22 | Laravel does not properly constrain the host portion of a password-reset URL |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2021-43808 | MODERATE | 0.8% | 6.20.42 | Laravel Framework XSS in Blade templating engine |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2025-27515 | MODERATE | 0.7% | 12.1.1 | Laravel has a File Validation Bypass |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2026-48019 | HIGH | 0.7% | 13.10.0 | Laravel Framework: CRLF injection in default email rule |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2024-13918 | MODERATE | 0.6% | 11.36.0 | Laravel framework susceptible to reflected cross-site scripting |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2024-13919 | MODERATE | 0.5% | 11.36.0 | Laravel framework susceptible to reflected cross-site scripting |
| phpunit/phpunit dev | ^10.5.35 || ^11.5.15 || ^12.5.8 || ^13.3.0 | CVE-2026-24765 | HIGH | 0.3% | 8.5.52 | PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling |
| phpunit/phpunit dev | ^10.5.35 || ^11.5.15 || ^12.5.8 || ^13.3.0 | CVE-2026-41570 | HIGH | 0.2% | 12.5.22 | PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | CVE-2019-9081 | CRITICAL | — | 6.20.44 | Laravel Framework Deserialization Vulnerability |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-qm5c-m76r-2hfr | CRITICAL | — | 6.18.31 | Laravel RCE vulnerability in "cookie" session driver |
| illuminate/database | ^11.44.2 || ^12.4.1 || ^13 | GHSA-4mg9-vhxq-vm7j | HIGH | — | 8.40.0 | SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database |
| illuminate/database | ^11.44.2 || ^12.4.1 || ^13 | GHSA-x7p5-p2c9-phvg | HIGH | — | 6.20.14 | Unexpected database bindings |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-4mg9-vhxq-vm7j | HIGH | — | 8.40.0 | SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-6jvx-8ch9-j2jr | HIGH | — | 5.6.30 | Laravel Cookie serialization vulnerability |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-jwvj-pwww-3mj5 | HIGH | — | 6.20.14 | laravel framework Unexpected database bindings via requests |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-wq8p-mqvg-2p5h | HIGH | — | 6.20.26 | laravel framework SQL Injection via limit and offset functions |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-x7p5-p2c9-phvg | HIGH | — | 6.20.14 | Unexpected database bindings |
| phpunit/phpunit dev | ^10.5.35 || ^11.5.15 || ^12.5.8 || ^13.3.0 | GHSA-mh6w-vxff-9wqp | HIGH | — | 12.5.22 | PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes |
| illuminate/database | ^11.44.2 || ^12.4.1 || ^13 | GHSA-cc2w-ghc5-m5qr | MODERATE | — | 4.1.29 | Laravel Risk of mass-assignment vulnerabilities |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-44pg-c29v-hp6r | MODERATE | — | 6.18.34 | Laravel Guard bypass in Eloquent models |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-7852-w36x-6mf6 | MODERATE | — | 5.5.40 | Laravel Encrypter Component Potential Decryption Failure Leading to Unintended Behavior |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-crmm-hgp2-wgrp | MODERATE | — | 13.12.0 | Laravel Framework: Temporary Signed URL Path Confusion |
| laravel/framework dev | ^11.44.2 || ^12.7.2 || ^13 | GHSA-p62r-7637-3wwc | MODERATE | — | 4.1.26 | Laravel Hijacked authentication cookies vulnerability |
+ 4 further findings (mostly lower severity) — available in the full export.
SBOM summary
17 direct dependencies scanned (0 pinned to exact versions) from composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.