facade CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

facade vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to facade, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-43996 The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control. [email protected] 9.8 0.50% 2021-11-17 2024-11-21
CVE-2021-3129 KEV Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2. [email protected] 9.8 94.29% 2021-01-12 2025-11-10
CVE-2020-13909 The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a consequence of the CVE-2021-43996 fix. [email protected] 9.8 0.43% 2020-06-07 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence