Icecoder/icecoder
by Nicecoder
Source repositories
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-63722 | Cri | 0.57 | 9.8 | — | Aug 19, 2026 | ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP… | ||
| CVE-2022-34026 | Hig | 0.49 | 7.5 | 0.01 | Sep 22, 2022 | ICEcoder v8.1 allows attackers to execute a directory traversal. | ||
| CVE-2024-41373 | Med | 0.41 | 6.3 | 0.00 | Jul 26, 2024 | ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php. | ||
| CVE-2024-41375 | Med | 0.40 | 6.1 | 0.00 | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php | ||
| CVE-2024-41374 | Med | 0.40 | 6.1 | 0.00 | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php | ||
| CVE-2021-3862 | Med | 0.24 | 4.8 | 0.01 | Jan 17, 2022 | icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
- risk 0.57cvss 9.8epss —
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP…
- risk 0.49cvss 7.5epss 0.01
ICEcoder v8.1 allows attackers to execute a directory traversal.
- risk 0.41cvss 6.3epss 0.00
ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.
- risk 0.40cvss 6.1epss 0.00
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
- risk 0.40cvss 6.1epss 0.00
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
- risk 0.24cvss 4.8epss 0.01
icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')