Products: 2
    Vulnerabilities: 13
    Known Exploited: 0
    1
    Critical Level Threats
    11
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-48557

    Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via FileAdder.php

    Last Modified: Jul 28, 2026
    Published: May 29, 2026

    CVE-2026-48555

    Spatie Laravel Media Library < 11.23.0 SSRF via addMediaFromUrl()

    Last Modified: Jul 28, 2026
    Published: May 29, 2026

    CVE-2025-3192

    Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.

    Last Modified: Apr 15, 2026
    Published: Apr 04, 2025

    CVE-2025-1022

    Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slashes in the file URI (e.g., file:../../../../etc/passwd). This is due to missing validations of the user input that should be blocking file URI schemes (e.g., file:// and file:/) in the HTML content. **Note:** Further analysis has identified additional proof-of-concept exploits leveraging the vulnerable function. Developers using this package should ensure proper input validation to mitigate potential risks, as the issue remains unaddressed.

    Last Modified: Jul 15, 2026
    Published: Feb 05, 2025

    CVE-2025-1026

    Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in a Local File Inclusion allowing the attacker to read sensitive files. **Note:** This is a bypass of the fix for [CVE-2024-21549](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8533023).

    Last Modified: Apr 15, 2026
    Published: Feb 05, 2025
    Items Per Page