StackDrift

End of life / Laravel / 6

Laravel 6 end of life

Laravel 6 reached end of life on 6 September 2022, 1,461 days ago. 16 known CVEs reach this release, the most severe rated CRITICAL.

The detail

Released
3 September 2019
End of life
6 September 2022
Countdown
1,461 days ago
Status
End of life
Long term support
Yes
Newest build on this release
6.20.45
Newest release overall
13.30.1

CVEs that reach 6

Advisory Severity CVSS Published Fixed in
GHSA-qm5c-m76r-2hfr
Laravel RCE vulnerability in "cookie" session driver
CRITICAL 9.9 15 May 2024 6.18.31
CVE-2019-9081
Laravel Framework Deserialization Vulnerability
CRITICAL 9.8 14 May 2022 6.20.44
GHSA-5vg9-5847-vvmq
Laravel Framework: CRLF injection in default email rule
HIGH 8.9 17 June 2026 12.60.0
CVE-2024-52301
Laravel environment manipulation via query string
HIGH 8.7 12 November 2024 6.20.45
CVE-2020-24941
An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.
HIGH 7.5 4 September 2020 6.18.35
CVE-2020-24940
An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.
HIGH 7.5 4 September 2020 6.18.34
GHSA-x7p5-p2c9-phvg
Unexpected database bindings
HIGH 7.2 2 February 2021 6.20.14
GHSA-wq8p-mqvg-2p5h
laravel framework SQL Injection via limit and offset functions
HIGH - 15 May 2024 6.20.26
GHSA-jwvj-pwww-3mj5
laravel framework Unexpected database bindings via requests
HIGH - 15 May 2024 6.20.14
GHSA-4mg9-vhxq-vm7j
SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database
HIGH - 29 April 2021 6.20.26
CVE-2025-27515
Laravel has a File Validation Bypass
MEDIUM 6.9 5 March 2025 10.48.29
CVE-2021-43808
Laravel Framework XSS in Blade templating engine
MEDIUM 6.1 8 December 2021 6.20.42
CVE-2021-21263
Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this w
MEDIUM 5.3 19 January 2021 6.20.12
GHSA-crmm-hgp2-wgrp
Laravel Framework: Temporary Signed URL Path Confusion
MEDIUM 4.2 17 June 2026 12.61.1
GHSA-44pg-c29v-hp6r
Laravel Guard bypass in Eloquent models
MEDIUM - 15 May 2024 6.18.34
CVE-2021-43617
Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content.
MEDIUM - 16 November 2021 no fixed version published

Where to move next

The newest tracked release is 13.30.1. If moving release is not an option yet, 6.20.45 is the newest build on the 6 line and needs no migration.

Other Laravel releases

Vendor sources last checked 6 September 2026, and checked daily. This data last changed on 6 September 2026.

You just looked this up by hand, for one version

StackDrift scans your machines, works out every version you actually run, and mails you before the next support window closes or a CVE lands on a build you have deployed. It covers the runtimes, operating systems and kernels underneath your code, not just your packages.

See pricing