CVE-2025-32931: Devdojo Voyager

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.

Affected products

  • Devdojo Voyager: from 1.4.0, up to and including 1.8.0

Published 2025-04-14. Last modified 2026-06-17.