<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Laravel</title><description>Actively exploited vulnerabilities affecting Laravel products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/laravel.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-54068 — Laravel Livewire Code Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-54068</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-54068</guid><description>Laravel Livewire, a popular PHP framework component for building dynamic web interfaces, contains a code injection flaw that lets unauthenticated attackers execute arbitrary commands on the server in certain configurations. No login or credentials are required to exploit this, making it particularly dangerous for any internet-facing application built on Livewire. Successful exploitation could give an attacker full control of the underlying server, enabling data theft, ransomware deployment, or further lateral movement.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><category>Laravel</category><category>Livewire</category></item></channel></rss>