Skip to content
Noroxi

facade records

3 published records for vendor facade.

Researcher profile

Entered KEV
1 · 33.3%
Weaponized
1 · 33.3%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
979 days

Records by year

  1. 20
  2. 21

Bar: total · dark part: CISA KEV.

Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    Attack profile

    All records

    3 records
    • Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of i

      CriticalCVSS 9.8KEVWeaponizedEPSS 100%

      laravel · laravelJan 12, 2021

    • The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect acc

      CriticalCVSS 9.8No exploitEPSS 2%

      facade · ignitionNov 17, 2021

    • The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env.

      CriticalCVSS 9.8No exploitEPSS 1%

      facade · ignitionJun 7, 2020