Skip to content
RequestGuard Vulnerabilities
Pricing

illuminate/database

The Illuminate Database package.

Composer latest 13.32.0 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

13.32.0

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

High

5 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

5

Query Binding Exploitation

Affected range

ECOSYSTEM: introduced 7.0.0; fixed 7.30.3ECOSYSTEM: introduced 8.0.0; fixed 8.22.1ECOSYSTEM: introduced 6.0.0; fixed 6.20.12>=6.0.0,<6.20.12|>=7.0.0,<7.30.3|>=8.0.0,<8.22.1

Fixed versions: 7.30.3, 8.22.1, 6.20.12

Unexpected database bindings

Affected range

ECOSYSTEM: introduced 0; fixed 6.20.14ECOSYSTEM: introduced 7.0.0; fixed 7.30.4ECOSYSTEM: introduced 8.0.0; fixed 8.24.0>=6.0.0,<6.20.14|>=7.0.0,<7.30.4|>=8.0.0,<8.24.0

Fixed versions: 6.20.14, 7.30.4, 8.24.0

SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database

Affected range

ECOSYSTEM: introduced 8.0.0; fixed 8.40.0ECOSYSTEM: introduced 0; fixed 6.20.26>=4.0.0,<4.0.99|>=4.1.0,<4.1.29

Fixed versions: 8.40.0, 6.20.26

Guard bypass in Eloquent models affecting Laravel illuminate database component

Affected range

ECOSYSTEM: introduced 5.5.0; last affected 5.5.44ECOSYSTEM: introduced 6.0.0; fixed 6.18.34ECOSYSTEM: introduced 7.0.0; fixed 7.23.2>=5.5.0,<=5.5.44|>=6.0.0,<6.18.34|>=7.0.0,<7.23.2

Fixed versions: 6.18.34, 7.23.2

Laravel Risk of mass-assignment vulnerabilities

Affected range

ECOSYSTEM: introduced 4.0.0; fixed 4.1.29>=6.0.0,<6.20.26|>=7.0.0,<7.30.5|>=8.0.0,<8.40.0

Fixed versions: 4.1.29