VYPR

KodExplorer

by KodExplorer

Source repositories

CVEs (4)

  • CVE-2025-34504MedDec 11, 2025
    risk 0.40cvss 6.1epss 0.00

    KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.

  • CVE-2023-49489MedDec 19, 2023
    risk 0.40cvss 6.1epss 0.01

    Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.

  • CVE-2021-36646MedSep 6, 2023
    risk 0.40cvss 6.1epss 0.01

    A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.

  • CVE-2023-37153MedJul 10, 2023
    risk 0.40cvss 6.1epss 0.01

    KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field.