Kodbox

Kodcloud · 14 CVEs

CVE-2026-1066
MEDIUM

kalcaddle kodbox Compression zip command injection

Jan 17, 2026

CVE-2025-10233
MEDIUM

kalcaddle kodbox editor.class.php fileSave path traversal

Sep 10, 2025

CVE-2025-9414
MEDIUM

kalcaddle kodbox Download from Link serverDownload server-side request forgery

Aug 25, 2025

CVE-2024-51037
MEDIUM

An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha featur…

Nov 15, 2024

CVE-2023-52069
MEDIUM

kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.

Jan 17, 2024

CVE-2023-52068
MEDIUM

kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.

Jan 16, 2024

CVE-2023-39691
CRITICAL

An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET r…

Jan 16, 2024

CVE-2023-6849
CRITICAL

kalcaddle kodbox app.php cover server-side request forgery

Dec 16, 2023

CVE-2023-6848
CRITICAL

kalcaddle kodbox index.class.php check command injection

Dec 16, 2023

CVE-2023-48028
CRITICAL

kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an a…

Nov 17, 2023

CVE-2023-45998
MEDIUM

kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.

Oct 23, 2023

CVE-2023-3607
HIGH

kodbox WebConsole Plug-In webconsole.php.txt Execute os command injection

Jul 10, 2023

CVE-2023-29790
HIGH

kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.

May 12, 2023

CVE-2023-29791
MEDIUM

kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.

May 11, 2023

Showing 1 to 14 of 14 CVEs