VYPR
Vendor

Kodcloud

Products
2
CVEs
41
Across products
41
Status
Private

Products

2

Recent CVEs

41
View all 41 CVEs →
  • CVE-2023-39691CriJan 16, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.

  • CVE-2023-48028CriNov 18, 2023
    risk 0.64cvss 9.8epss 0.01

    kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.

  • CVE-2023-29790HigMay 12, 2023
    risk 0.49cvss 7.5epss 0.01

    kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.

  • CVE-2026-6569HigApr 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be…

  • CVE-2026-6568HigApr 19, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack…

  • CVE-2026-8753MedMay 17, 2026
    risk 0.41cvss 6.3epss 0.01

    A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component fileThumb Plugin. The manipulation of the argument ffmpegBin…

  • CVE-2026-6571MedApr 19, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack…

  • CVE-2026-4589MedMar 23, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side…

  • CVE-2026-2560MedFeb 16, 2026
    risk 0.41cvss 6.3epss 0.02

    A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command…

  • CVE-2026-1066MedJan 17, 2026
    risk 0.41cvss 6.3epss 0.05

    A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Compression Handler. The manipulation results in command injection. The attack may be launched remotely. The exploit is…

  • CVE-2025-10233MedSep 10, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit…

  • CVE-2025-34504MedDec 11, 2025
    risk 0.40cvss 6.1epss 0.00

    KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.

  • CVE-2023-52068MedJan 16, 2024
    risk 0.40cvss 6.1epss 0.00

    kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.

  • CVE-2023-49489MedDec 19, 2023
    risk 0.40cvss 6.1epss 0.01

    Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.

  • CVE-2021-36646MedSep 6, 2023
    risk 0.40cvss 6.1epss 0.01

    A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.

  • CVE-2023-37153MedJul 10, 2023
    risk 0.40cvss 6.1epss 0.01

    KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field.

  • CVE-2023-29791MedMay 11, 2023
    risk 0.40cvss 6.1epss 0.00

    kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.

  • CVE-2026-5618MedApr 6, 2026
    risk 0.36cvss 5.6epss 0.00

    A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out…

  • CVE-2026-4830MedMar 26, 2026
    risk 0.36cvss 5.6epss 0.00

    A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This…

  • CVE-2026-4592MedMar 23, 2026
    risk 0.36cvss 5.6epss 0.00

    A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of the component Password Login. The manipulation leads to improper…