backpack/crud vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-57570Mediumbackpack/crud: Laravel Backpack CRUD: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelationCVE-2026-54182Highbackpack/crud: Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)CVE-2026-54181Mediumbackpack/crud: Laravel Backpack CRUD: Stored XSS in the color column — the `@if($column['escaped'])` branches are invertedCVE-2026-54180Highbackpack/crud: Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)CVE-2026-54179Mediumbackpack/crud: Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix — SVG-with-script lands on the public diskCVE-2026-54178Highbackpack/crud: Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDiskCVE-2026-54177Mediumbackpack/crud: Laravel Backpack CRUD: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserverCVE-2026-54176Mediumbackpack/crud: Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password checkCVE-2026-54175Highbackpack/crud: Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignmentCVE-2022-31114Mediumbackpack/crud: backpack/crud is vulnerable to Cross-Site Scripting (XSS)CVE-2018-20962Mediumbackpack/crud: Backpack\CRUD for Laravel XSS Vulnerability

Stop the waste.
Protect your environment with Kodem.