End of life / Laravel / 8
Laravel 8 end of life
Laravel 8 reached end of life on 24 January 2023, 1,321 days ago. 12 known CVEs reach this release, the most severe rated CRITICAL.
The detail
- Released
- 8 September 2020
- End of life
- 24 January 2023
- Countdown
- 1,321 days ago
- Status
- End of life
- Long term support
- No
- Newest build on this release
- 8.83.29
- Newest release overall
- 13.30.1
CVEs that reach 8
| Advisory | Severity | CVSS | Published | Fixed in |
|---|---|---|---|---|
| CVE-2021-28254 A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands. | CRITICAL | 9.8 | 19 April 2023 | no fixed version published |
| GHSA-5vg9-5847-vvmq Laravel Framework: CRLF injection in default email rule | HIGH | 8.9 | 17 June 2026 | 12.60.0 |
| CVE-2024-52301 Laravel environment manipulation via query string | HIGH | 8.7 | 12 November 2024 | 8.83.28 |
| GHSA-x7p5-p2c9-phvg Unexpected database bindings | HIGH | 7.2 | 2 February 2021 | 8.24.0 |
| GHSA-wq8p-mqvg-2p5h laravel framework SQL Injection via limit and offset functions | HIGH | - | 15 May 2024 | 8.40.0 |
| GHSA-jwvj-pwww-3mj5 laravel framework Unexpected database bindings via requests | HIGH | - | 15 May 2024 | 8.24.0 |
| GHSA-4mg9-vhxq-vm7j SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database | HIGH | - | 29 April 2021 | 8.40.0 |
| CVE-2025-27515 Laravel has a File Validation Bypass | MEDIUM | 6.9 | 5 March 2025 | 10.48.29 |
| CVE-2021-43808 Laravel Framework XSS in Blade templating engine | MEDIUM | 6.1 | 8 December 2021 | 8.75.0 |
| CVE-2021-21263 Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this w | MEDIUM | 5.3 | 19 January 2021 | 8.22.1 |
| GHSA-crmm-hgp2-wgrp Laravel Framework: Temporary Signed URL Path Confusion | MEDIUM | 4.2 | 17 June 2026 | 12.61.1 |
| CVE-2021-43617 Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content. | MEDIUM | - | 16 November 2021 | no fixed version published |
Where to move next
The newest tracked release is 13.30.1. If moving release is not an option yet, 8.83.29 is the newest build on the 8 line and needs no migration.
Other Laravel releases
Vendor sources last checked 6 September 2026, and checked daily. This data last changed on 6 September 2026.
You just looked this up by hand, for one version
StackDrift scans your machines, works out every version you actually run, and mails you before the next support window closes or a CVE lands on a build you have deployed. It covers the runtimes, operating systems and kernels underneath your code, not just your packages.