CVE-2025-14894
EUVD-2026-294716.01.2026, 13:16
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| livewire-filemanager | filemanager | 𝑥 < 1.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration