VYPR

Icecoder/icecoder

by Nicecoder

Source repositories

CVEs (10)

  • CVE-2026-63722CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP…

  • CVE-2026-64837HigSep 10, 2026
    risk 0.50cvss 8.8epss 0.01

    ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties…

  • CVE-2026-64836HigSep 10, 2026
    risk 0.50cvss 8.8epss 0.00

    ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated…

  • CVE-2022-34026HigSep 22, 2022
    risk 0.49cvss 7.5epss 0.02

    ICEcoder v8.1 allows attackers to execute a directory traversal.

  • CVE-2026-64838HigSep 10, 2026
    risk 0.47cvss 8.3epss 0.00

    ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable…

  • CVE-2024-41373MedJul 26, 2024
    risk 0.41cvss 6.3epss 0.00

    ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.

  • CVE-2024-41375MedJul 26, 2024
    risk 0.40cvss 6.1epss 0.00

    ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php

  • CVE-2024-41374MedJul 26, 2024
    risk 0.40cvss 6.1epss 0.00

    ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php

  • CVE-2021-32106MedJun 8, 2021
    risk 0.28cvss 5.4epss 0.01

    In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.

  • CVE-2021-3862MedJan 17, 2022
    risk 0.24cvss 4.8epss 0.01

    icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')