Logo b4r
blog cve me tags projects
  1. Tags
  2. laravel
  • another sharp authz bug, this time in quick creation

    cve-2026-53634 let authenticated sharp users bypass create authorization through quick creation command endpoints

    b b4r
    June 10, 2026
    2 min read
    vulnerability cve web exploitation laravel
  • a neat little cve in filament

    cve-2026-48067 came from a scope mismatch in filament AttachAction and AssociateAction

    b b4r
    May 25, 2026
    3 min read
    vulnerability cve web exploitation laravel
  • six cves in one open-source e-commerce project

    how i reported six shopper cves spanning authorization bypass, privilege escalation, race conditions, idor, and xss

    b b4r
    May 22, 2026
    5 min read
    vulnerability advisory cve web exploitation laravel
  • my first CVE, CVE-2026-44692

    authenticated sharp users could download unrelated laravel storage objects through the generic download endpoint

    b b4r
    May 8, 2026
    7 min read
    vulnerability cve web exploitation laravel
© 2026 All rights reserved.