Kodcloud
Products
2- 27 CVEs
- 14 CVEs
Recent CVEs
41| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39691 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2024 | An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request. | ||
| CVE-2023-48028 | Cri | 0.64 | 9.8 | 0.01 | Nov 18, 2023 | kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack. | ||
| CVE-2023-29790 | Hig | 0.49 | 7.5 | 0.01 | May 12, 2023 | kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue. | ||
| CVE-2026-6569 | Hig | 0.47 | 7.3 | 0.00 | Apr 19, 2026 | A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be… | ||
| CVE-2026-6568 | Hig | 0.47 | 7.3 | 0.01 | Apr 19, 2026 | A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack… | ||
| CVE-2026-8753 | Med | 0.41 | 6.3 | 0.01 | May 17, 2026 | A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component fileThumb Plugin. The manipulation of the argument ffmpegBin… | ||
| CVE-2026-6571 | Med | 0.41 | 6.3 | 0.00 | Apr 19, 2026 | A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack… | ||
| CVE-2026-4589 | Med | 0.41 | 6.3 | 0.00 | Mar 23, 2026 | A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side… | ||
| CVE-2026-2560 | Med | 0.41 | 6.3 | 0.02 | Feb 16, 2026 | A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command… | ||
| CVE-2026-1066 | Med | 0.41 | 6.3 | 0.05 | Jan 17, 2026 | A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Compression Handler. The manipulation results in command injection. The attack may be launched remotely. The exploit is… | ||
| CVE-2025-10233 | Med | 0.41 | 6.3 | 0.00 | Sep 10, 2025 | A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit… | ||
| CVE-2025-34504 | Med | 0.40 | 6.1 | 0.00 | Dec 11, 2025 | KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication. | ||
| CVE-2023-52068 | Med | 0.40 | 6.1 | 0.00 | Jan 16, 2024 | kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs. | ||
| CVE-2023-49489 | Med | 0.40 | 6.1 | 0.01 | Dec 19, 2023 | Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php. | ||
| CVE-2021-36646 | Med | 0.40 | 6.1 | 0.01 | Sep 6, 2023 | A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page. | ||
| CVE-2023-37153 | Med | 0.40 | 6.1 | 0.01 | Jul 10, 2023 | KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field. | ||
| CVE-2023-29791 | Med | 0.40 | 6.1 | 0.00 | May 11, 2023 | kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information. | ||
| CVE-2026-5618 | Med | 0.36 | 5.6 | 0.00 | Apr 6, 2026 | A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out… | ||
| CVE-2026-4830 | Med | 0.36 | 5.6 | 0.00 | Mar 26, 2026 | A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This… | ||
| CVE-2026-4592 | Med | 0.36 | 5.6 | 0.00 | Mar 23, 2026 | A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of the component Password Login. The manipulation leads to improper… |
- risk 0.64cvss 9.8epss 0.01
An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.
- risk 0.64cvss 9.8epss 0.01
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
- risk 0.49cvss 7.5epss 0.01
kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.
- risk 0.47cvss 7.3epss 0.00
A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be…
- risk 0.47cvss 7.3epss 0.01
A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack…
- risk 0.41cvss 6.3epss 0.01
A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component fileThumb Plugin. The manipulation of the argument ffmpegBin…
- risk 0.41cvss 6.3epss 0.00
A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side…
- risk 0.41cvss 6.3epss 0.02
A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command…
- risk 0.41cvss 6.3epss 0.05
A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Compression Handler. The manipulation results in command injection. The attack may be launched remotely. The exploit is…
- risk 0.41cvss 6.3epss 0.00
A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit…
- risk 0.40cvss 6.1epss 0.00
KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.
- risk 0.40cvss 6.1epss 0.00
kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
- risk 0.40cvss 6.1epss 0.01
Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.
- risk 0.40cvss 6.1epss 0.01
A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.
- risk 0.40cvss 6.1epss 0.01
KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field.
- risk 0.40cvss 6.1epss 0.00
kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.
- risk 0.36cvss 5.6epss 0.00
A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out…
- risk 0.36cvss 5.6epss 0.00
A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This…
- risk 0.36cvss 5.6epss 0.00
A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of the component Password Login. The manipulation leads to improper…