Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-3129

Quick assessment

Affected
n/a n/a
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Facade Ignition for Laravel是比利时Facade公司的一款运行在Laravel Web框架中的可自定义的错误页面。 Ignition for Laravel 2.5.2之前版本存在授权问题漏洞,该漏洞源于程序未进行正确的身份验证,攻击者可利用该漏洞执行任意代码。

AI Predicted 9.8 Difficulty: Trivial KEV · Ransomware EPSS 99.94% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-3129

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Facade Ignition for Laravel 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Facade Ignition for Laravel是比利时Facade公司的一款运行在Laravel Web框架中的可自定义的错误页面。 Ignition for Laravel 2.5.2之前版本存在授权问题漏洞,该漏洞源于程序未进行正确的身份验证,攻击者可利用该漏洞执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2021-3129

# POC Description Source Link Shenlong Link
1 Exploit for CVE-2021-3129 https://github.com/ambionics/laravel-exploits POC Details
2 Laravel debug rce https://github.com/SNCKER/CVE-2021-3129 POC Details
3 None https://github.com/SecPros-Team/laravel-CVE-2021-3129-EXP POC Details
4 None https://github.com/crisprss/Laravel_CVE-2021-3129_EXP POC Details
5 Exploit for CVE-2021-3129 https://github.com/nth347/CVE-2021-3129_exploit POC Details
6 None https://github.com/FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129 POC Details
7 Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129) https://github.com/zhzyker/CVE-2021-3129 POC Details
8 CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞 https://github.com/simonlee-hello/CVE-2021-3129 POC Details
9 None https://github.com/idea-oss/laravel-CVE-2021-3129-EXP POC Details
10 PoC for CVE-2021-3129 (Laravel) https://github.com/knqyf263/CVE-2021-3129 POC Details
11 Add revert shell https://github.com/cuongtop4598/CVE-2021-3129-Script POC Details
12 Laravel RCE (CVE-2021-3129) https://github.com/joshuavanderpoll/CVE-2021-3129 POC Details
13 CVE-2021-3129 POC https://github.com/shadowabi/Laravel-CVE-2021-3129 POC Details
14 Unauthenticated RCE in Laravel Debug Mode <8.4.2 https://github.com/JacobEbben/CVE-2021-3129 POC Details
15 Laravel debug mode - Remote Code Execution (RCE) https://github.com/hupe1980/CVE-2021-3129 POC Details
16 CVE-2021-3129-Laravel Debug mode https://github.com/0nion1/CVE-2021-3129 POC Details
17 CVE-2021-3129 Exploit Checker By ./MrMad https://github.com/MadExploits/Laravel-debug-Checker POC Details
18 Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp https://github.com/ajisai-babu/CVE-2021-3129-exp POC Details
19 Laravel RCE CVE-2021-3129 https://github.com/keyuan15/CVE-2021-3129 POC Details
20 None https://github.com/qaisarafridi/cve-2021-3129 POC Details
21 None https://github.com/Zoo1sondv/CVE-2021-3129 POC Details
22 Laravel RCE (CVE-2021-3129) https://github.com/miko550/CVE-2021-3129 POC Details
23 CVE-2021-3129 | Laravel Debug Mode Vulnerability https://github.com/withmasday/CVE-2021-3129 POC Details
24 None https://github.com/banyaksepuh/Mass-CVE-2021-3129-Scanner POC Details
25 None https://github.com/Axianke/CVE-2021-3129 POC Details
26 A exploit script for CVE-2021-3129 https://github.com/cc3305/CVE-2021-3129 POC Details
27 CVE-2021-3129 | Laravel Debug Mode Vulnerability https://github.com/wmasday/CVE-2021-3129 POC Details
28 Laravel Debug Mode and Payload https://github.com/piperpwn/CVE-2021-3129- POC Details
29 CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞 https://github.com/Y0s9/CVE-2021-3129 POC Details
30 CVE-2021-3129 Laravel Ignition RCE Exploit https://github.com/0x0d3ad/CVE-2021-3129 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-3129

请登录查看更多情报信息。

Patches & Fixes for CVE-2021-3129 (1)

Exploits & Public PoCs for CVE-2021-3129 (1)

Security Blog Posts for CVE-2021-3129 (1)

Same Patch Batch · n/a · 2021-01-12 · 32 CVEs total

CVE-2020-35459 Clusterlabs Crmsh 安全漏洞
CVE-2021-23927 Open-xchange OX App Suite 代码问题漏洞
CVE-2021-23928 Open-xchange OX App Suite 跨站脚本漏洞
CVE-2021-23929 Open-xchange OX App Suite 跨站脚本漏洞
CVE-2021-23930 Open-xchange OX App Suite 跨站脚本漏洞
CVE-2021-23931 Open-xchange OX App Suite 跨站脚本漏洞
CVE-2021-23932 Open-xchange OX App Suite 跨站脚本漏洞
CVE-2021-23933 Open-xchange OX App Suite 跨站脚本漏洞
CVE-2021-23934 Open-xchange OX App Suite 跨站脚本漏洞
CVE-2021-23935 Open-xchange OX App Suite 跨站脚本漏洞
CVE-2021-23936 Open-xchange OX App Suite 跨站脚本漏洞
CVE-2020-36190 RailsAdmin 跨站脚本漏洞
CVE-2021-3134 北京坤豆 Mubu 授权问题漏洞
CVE-2021-3133 WordPress Elementor Contact Form DB plugin 跨站请求伪造漏洞
CVE-2020-13116 Opentext Carbonite 跨站脚本漏洞
CVE-2020-25657 m2crypto 安全漏洞
CVE-2020-27637 R Cran 路径遍历漏洞
CVE-2020-14274 HCL Commerce 信息泄露漏洞
CVE-2020-14275 HCL Commerce 安全漏洞
CVE-2020-35458 ClusterLabs Hawk 代码注入漏洞

Showing top 20 of 32 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2021-3129

Anonymous User
2026-08-03 09:37:45

1

Anonymous User
2026-08-03 09:37:45

1'

Anonymous User
2026-08-03 09:37:46

1' ORDER BY 1-- -

Anonymous User
2026-08-03 09:37:47

1' ORDER BY 2-- -

Anonymous User
2026-08-03 09:37:47

1' ORDER BY 3-- -

Anonymous User
2026-08-03 09:37:48

1' ORDER BY 4-- -

Anonymous User
2026-08-03 09:37:48

1' ORDER BY 5-- -

Anonymous User
2026-08-03 09:37:48

1' ORDER BY 6-- -

Anonymous User
2026-08-03 09:37:48

1' ORDER BY 7-- -

Anonymous User
2026-08-03 09:37:49

1' ORDER BY 8-- -

Anonymous User
2026-08-03 09:37:50

1' ORDER BY 9-- -

Anonymous User
2026-08-03 09:37:51

1' ORDER BY 10-- -

Anonymous User
2026-08-03 09:37:51

1

Anonymous User
2026-08-03 09:37:51

1'XOR((SELECT(1)FROM(SELECT(if(now()=sysdate(),sleep(5),0)))A))OR'

Anonymous User
2026-08-03 09:37:52

1' AND SLEEP(5)-- -

Anonymous User
2026-08-03 09:37:52

1 AND SLEEP(5)-- -

Anonymous User
2026-08-03 09:37:53

1';WAITFOR DELAY '0:0:5'-- -

Anonymous User
2026-08-03 09:37:53

1' AND 1=(SELECT 1 FROM pg_sleep(5))-- -


Leave a comment