Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-54108 | |
Github GHSA |
GHSA-m8xx-3x29-84h8 | backpack/crud is vulnerable to Cross-Site Scripting (XSS) |
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Laravel-backpack
Laravel-backpack crud |
|
| Vendors & Products |
Laravel-backpack
Laravel-backpack crud |
Wed, 03 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.69, and 4.0.63 are vulnerable to cross-site scripting. An attacker could conduct a targeted phishing campaign, in order to trick users or admins into clicking a malicious link, which under very specific circumstances could give them information or possibly admin access. Versions 5.0.13, 4.1.69, and 4.0.63 patch the issue. As a workaround, manually look inside error views in `resources/views/errors` and output `e($exception->getMessage())` instead of `$exception->getMessage()`. | |
| Title | backpack/crud Vulnerable to Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T16:01:22.313Z
Reserved: 2022-05-18T18:37:25.429Z
Link: CVE-2022-31114
Updated: 2026-06-03T16:01:19.401Z
Status : Deferred
Published: 2026-06-03T16:16:18.597
Modified: 2026-06-04T16:18:41.697
Link: CVE-2022-31114
No data.
OpenCVE Enrichment
Updated: 2026-06-05T10:11:31Z
EUVD
Github GHSA