logo

Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks

ID: 3a9e6929-2fe6-553c-acaf-f12806e3b27d

STIX ID: report--3a9e6929-2fe6-553c-acaf-f12806e3b27d

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2025-14894 / VU#650657) in Livewire Filemanager allows attackers to upload and execute PHP webshells via the Laravel storage link; CERT/CC advises immediate mitigations including disabling public storage links, enforcing strict upload allowlists and MIME validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.