The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| laravel/framework(Packagist) | 11.9.0 | 11.36.0 | N/A |
CVSS Metrics