CVE-2020-24940: Laravel

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.

Affected products

  • Laravel Laravel: before 6.18.34 (fixed in 6.18.34); from 7.0.0, before 7.23.2 (fixed in 7.23.2)

Published 2020-09-04. Last modified 2026-06-17.