CRAIR CRA Readiness Snapshot

larastan/larastan · composer.json · 15 Sep 2026, 00:11 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
17
dependencies in scope
34
known vulnerabilities
2
actively exploited (CISA KEV)
100.0%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 2 findings are in the CISA KEV catalog (0 in production dependencies):

PackageYour versionCVEFixed inExploit context
phpunit/phpunit dev ^10.5.35 || ^11.5.15 || ^12.5.8 || ^13.3.0 (unpinned) CVE-2017-9841 4.8.28 KEV listed 2022-02-15
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 (unpinned) CVE-2018-15133 5.6.30 KEV listed 2024-01-16

⚠ No lockfile — SBOM is not reproducible

This scan is based on a manifest (composer.json), not a lockfile. 17 of 17 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.

All findings (34)

PackageVersionAdvisorySeverityEPSSFixed inSummary
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2024-52301 HIGH 44.8% 6.20.45 Laravel environment manipulation via query string
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2020-19316 HIGH 2.5% 5.8.17 OS Command Injection in Laravel Framework
illuminate/database ^11.44.2 || ^12.4.1 || ^13 CVE-2021-21263 HIGH 1.6% 7.30.3 Query Binding Exploitation
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2021-21263 HIGH 1.6% 8.22.1 Query Binding Exploitation
illuminate/database ^11.44.2 || ^12.4.1 || ^13 CVE-2020-24940 HIGH 1.2% 6.18.34 Guard bypass in Eloquent models affecting Laravel illuminate database component
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2017-14775 MODERATE 1.2% 5.5.10 Laravel Sensitive Data Exposure
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2020-24941 HIGH 1.1% 6.18.35 Improper Input Validation in Laravel
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2017-9303 MODERATE 1.0% 5.4.22 Laravel does not properly constrain the host portion of a password-reset URL
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2021-43808 MODERATE 0.8% 6.20.42 Laravel Framework XSS in Blade templating engine
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2025-27515 MODERATE 0.7% 12.1.1 Laravel has a File Validation Bypass
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2026-48019 HIGH 0.7% 13.10.0 Laravel Framework: CRLF injection in default email rule
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2024-13918 MODERATE 0.6% 11.36.0 Laravel framework susceptible to reflected cross-site scripting
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2024-13919 MODERATE 0.5% 11.36.0 Laravel framework susceptible to reflected cross-site scripting
phpunit/phpunit dev ^10.5.35 || ^11.5.15 || ^12.5.8 || ^13.3.0 CVE-2026-24765 HIGH 0.3% 8.5.52 PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling
phpunit/phpunit dev ^10.5.35 || ^11.5.15 || ^12.5.8 || ^13.3.0 CVE-2026-41570 HIGH 0.2% 12.5.22 PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 CVE-2019-9081 CRITICAL 6.20.44 Laravel Framework Deserialization Vulnerability
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-qm5c-m76r-2hfr CRITICAL 6.18.31 Laravel RCE vulnerability in "cookie" session driver
illuminate/database ^11.44.2 || ^12.4.1 || ^13 GHSA-4mg9-vhxq-vm7j HIGH 8.40.0 SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database
illuminate/database ^11.44.2 || ^12.4.1 || ^13 GHSA-x7p5-p2c9-phvg HIGH 6.20.14 Unexpected database bindings
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-4mg9-vhxq-vm7j HIGH 8.40.0 SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-6jvx-8ch9-j2jr HIGH 5.6.30 Laravel Cookie serialization vulnerability
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-jwvj-pwww-3mj5 HIGH 6.20.14 laravel framework Unexpected database bindings via requests
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-wq8p-mqvg-2p5h HIGH 6.20.26 laravel framework SQL Injection via limit and offset functions
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-x7p5-p2c9-phvg HIGH 6.20.14 Unexpected database bindings
phpunit/phpunit dev ^10.5.35 || ^11.5.15 || ^12.5.8 || ^13.3.0 GHSA-mh6w-vxff-9wqp HIGH 12.5.22 PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
illuminate/database ^11.44.2 || ^12.4.1 || ^13 GHSA-cc2w-ghc5-m5qr MODERATE 4.1.29 Laravel Risk of mass-assignment vulnerabilities
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-44pg-c29v-hp6r MODERATE 6.18.34 Laravel Guard bypass in Eloquent models
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-7852-w36x-6mf6 MODERATE 5.5.40 Laravel Encrypter Component Potential Decryption Failure Leading to Unintended Behavior
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-crmm-hgp2-wgrp MODERATE 13.12.0 Laravel Framework: Temporary Signed URL Path Confusion
laravel/framework dev ^11.44.2 || ^12.7.2 || ^13 GHSA-p62r-7637-3wwc MODERATE 4.1.26 Laravel Hijacked authentication cookies vulnerability

+ 4 further findings (mostly lower severity) — available in the full export.

SBOM summary

17 direct dependencies scanned (0 pinned to exact versions) from composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us