Codologic / Codoforum
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-22540 | Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payl… | MEDIUM | 5.4 | Apr 15, 2024 |
| CVE-2020-22539 | An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file. | HIGH | 7.2 | Apr 15, 2024 |
| CVE-2022-31854 | Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel. | HIGH | 7.2 | Jul 7, 2022 |
| CVE-2020-25875 | A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts… | MEDIUM | 5.4 | Jul 9, 2021 |
| CVE-2020-25876 | A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or… | MEDIUM | 5.4 | Jul 9, 2021 |
| CVE-2020-25879 | A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scr… | MEDIUM | 5.4 | Jul 9, 2021 |
| CVE-2020-13873 | A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass t… | CRITICAL | 9.8 | May 12, 2021 |
| CVE-2020-9007 | Codoforum 4.8.8 allows self-XSS via the title of a new topic. | MEDIUM | 5.4 | Feb 16, 2020 |
| CVE-2020-7050 | Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loade… | MEDIUM | 5.4 | Feb 15, 2020 |
| CVE-2020-7051 | Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the Http… | MEDIUM | 6.1 | Feb 13, 2020 |
| CVE-2020-5842 | Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed o… | MEDIUM | 6.1 | Jan 7, 2020 |
| CVE-2020-5843 | Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen. | MEDIUM | 4.8 | Jan 7, 2020 |
| CVE-2020-5306 | Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content. | MEDIUM | 4.8 | Jan 5, 2020 |
| CVE-2020-5305 | Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen. | MEDIUM | 4.8 | Jan 5, 2020 |
| CVE-2014-9261 | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitra… | MEDIUM | 5.0 | Mar 23, 2015 |
Showing 1 to 15 of 15 CVEs