Kodbox
by Kodcloud
Source repositories
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39691 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2024 | An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request. | ||
| CVE-2023-48028 | Cri | 0.64 | 9.8 | 0.01 | Nov 18, 2023 | kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack. | ||
| CVE-2023-29790 | Hig | 0.49 | 7.5 | 0.01 | May 12, 2023 | kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue. | ||
| CVE-2026-8753 | Med | 0.41 | 6.3 | 0.01 | May 17, 2026 | A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component fileThumb Plugin. The manipulation of the argument ffmpegBin… | ||
| CVE-2026-4589 | Med | 0.41 | 6.3 | 0.00 | Mar 23, 2026 | A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side… | ||
| CVE-2026-2560 | Med | 0.41 | 6.3 | 0.02 | Feb 16, 2026 | A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command… | ||
| CVE-2026-1066 | Med | 0.41 | 6.3 | 0.05 | Jan 17, 2026 | A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Compression Handler. The manipulation results in command injection. The attack may be launched remotely. The exploit is… | ||
| CVE-2025-10233 | Med | 0.41 | 6.3 | 0.00 | Sep 10, 2025 | A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit… | ||
| CVE-2023-52068 | Med | 0.40 | 6.1 | 0.00 | Jan 16, 2024 | kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs. | ||
| CVE-2023-29791 | Med | 0.40 | 6.1 | 0.00 | May 11, 2023 | kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information. | ||
| CVE-2026-5618 | Med | 0.36 | 5.6 | 0.00 | Apr 6, 2026 | A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out… | ||
| CVE-2026-4830 | Med | 0.36 | 5.6 | 0.00 | Mar 26, 2026 | A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This… | ||
| CVE-2026-4592 | Med | 0.36 | 5.6 | 0.00 | Mar 23, 2026 | A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of the component Password Login. The manipulation leads to improper… | ||
| CVE-2023-3607 | Med | 0.36 | 5.5 | 0.06 | Jul 10, 2023 | A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Execute of the file webconsole.php.txt of the component WebConsole Plug-In. The manipulation leads to os command injection. The exploit has been disclosed to the… | ||
| CVE-2023-52069 | Med | 0.35 | 5.4 | 0.00 | Jan 17, 2024 | kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter. | ||
| CVE-2023-45998 | Med | 0.35 | 5.4 | 0.00 | Oct 23, 2023 | kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS. | ||
| CVE-2026-18720 | Med | 0.34 | 5.3 | 0.00 | Aug 4, 2026 | A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to improper authorization. It is possible to launch the attack… | ||
| CVE-2024-51037 | Med | 0.34 | 5.3 | 0.00 | Nov 15, 2024 | An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function. | ||
| CVE-2026-4591 | Med | 0.31 | 4.7 | 0.03 | Mar 23, 2026 | A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/source-code/plugins/fileThumb/app.php of the component fileThumb Endpoint. Executing a manipulation can lead to os command injection. The attack can be executed… | ||
| CVE-2025-9414 | Med | 0.31 | 4.7 | 0.00 | Aug 25, 2025 | A vulnerability was found in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the file /?explorer/upload/serverDownload of the component Download from Link Handler. Performing manipulation of the argument url results in server-side request… |
- risk 0.64cvss 9.8epss 0.01
An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.
- risk 0.64cvss 9.8epss 0.01
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
- risk 0.49cvss 7.5epss 0.01
kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.
- risk 0.41cvss 6.3epss 0.01
A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component fileThumb Plugin. The manipulation of the argument ffmpegBin…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side…
- risk 0.41cvss 6.3epss 0.02
A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command…
- risk 0.41cvss 6.3epss 0.05
A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Compression Handler. The manipulation results in command injection. The attack may be launched remotely. The exploit is…
- risk 0.41cvss 6.3epss 0.00
A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit…
- risk 0.40cvss 6.1epss 0.00
kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
- risk 0.40cvss 6.1epss 0.00
kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.
- risk 0.36cvss 5.6epss 0.00
A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out…
- risk 0.36cvss 5.6epss 0.00
A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This…
- risk 0.36cvss 5.6epss 0.00
A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of the component Password Login. The manipulation leads to improper…
- risk 0.36cvss 5.5epss 0.06
A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Execute of the file webconsole.php.txt of the component WebConsole Plug-In. The manipulation leads to os command injection. The exploit has been disclosed to the…
- risk 0.35cvss 5.4epss 0.00
kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.
- risk 0.35cvss 5.4epss 0.00
kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.
- risk 0.34cvss 5.3epss 0.00
A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to improper authorization. It is possible to launch the attack…
- risk 0.34cvss 5.3epss 0.00
An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.
- risk 0.31cvss 4.7epss 0.03
A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/source-code/plugins/fileThumb/app.php of the component fileThumb Endpoint. Executing a manipulation can lead to os command injection. The attack can be executed…
- risk 0.31cvss 4.7epss 0.00
A vulnerability was found in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the file /?explorer/upload/serverDownload of the component Download from Link Handler. Performing manipulation of the argument url results in server-side request…
Page 1 of 2