Icecoder
by Nicecoder
Source repositories
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-64837 | Hig | 0.50 | 8.8 | 0.01 | Sep 10, 2026 | ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties… | ||
| CVE-2026-64836 | Hig | 0.50 | 8.8 | 0.00 | Sep 10, 2026 | ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated… | ||
| CVE-2022-34026 | Hig | 0.49 | 7.5 | 0.02 | Sep 22, 2022 | ICEcoder v8.1 allows attackers to execute a directory traversal. | ||
| CVE-2026-64838 | Hig | 0.47 | 8.3 | 0.00 | Sep 10, 2026 | ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable… | ||
| CVE-2024-41373 | Med | 0.41 | 6.3 | 0.00 | Jul 26, 2024 | ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php. | ||
| CVE-2024-41375 | Med | 0.40 | 6.1 | 0.00 | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php | ||
| CVE-2024-41374 | Med | 0.40 | 6.1 | 0.00 | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php | ||
| CVE-2021-32106 | Med | 0.28 | 5.4 | 0.01 | Jun 8, 2021 | In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed. | ||
| CVE-2021-3862 | Med | 0.24 | 4.8 | 0.01 | Jan 17, 2022 | icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
- risk 0.50cvss 8.8epss 0.01
ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties…
- risk 0.50cvss 8.8epss 0.00
ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated…
- risk 0.49cvss 7.5epss 0.02
ICEcoder v8.1 allows attackers to execute a directory traversal.
- risk 0.47cvss 8.3epss 0.00
ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable…
- risk 0.41cvss 6.3epss 0.00
ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.
- risk 0.40cvss 6.1epss 0.00
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
- risk 0.40cvss 6.1epss 0.00
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
- risk 0.28cvss 5.4epss 0.01
In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.
- risk 0.24cvss 4.8epss 0.01
icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')