Kodbox
Kodcloud · 14 CVEs
kalcaddle kodbox Compression zip command injection
Jan 17, 2026
kalcaddle kodbox editor.class.php fileSave path traversal
Sep 10, 2025
kalcaddle kodbox Download from Link serverDownload server-side request forgery
Aug 25, 2025
An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha featur…
Nov 15, 2024
kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.
Jan 17, 2024
kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
Jan 16, 2024
An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET r…
Jan 16, 2024
kalcaddle kodbox app.php cover server-side request forgery
Dec 16, 2023
kalcaddle kodbox index.class.php check command injection
Dec 16, 2023
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an a…
Nov 17, 2023
kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.
Oct 23, 2023
kodbox WebConsole Plug-In webconsole.php.txt Execute os command injection
Jul 10, 2023
kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.
May 12, 2023
kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.
May 11, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-1066 | kalcaddle kodbox Compression zip command injection | MEDIUM | 5.55% | Jan 17, 2026 |
| CVE-2025-10233 | kalcaddle kodbox editor.class.php fileSave path traversal | MEDIUM | 0.46% | Sep 10, 2025 |
| CVE-2025-9414 | kalcaddle kodbox Download from Link serverDownload server-side request forgery | MEDIUM | 0.30% | Aug 25, 2025 |
| CVE-2024-51037 | An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function. | MEDIUM | 0.28% | Nov 15, 2024 |
| CVE-2023-52069 | kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter. | MEDIUM | 0.29% | Jan 17, 2024 |
| CVE-2023-52068 | kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs. | MEDIUM | 0.31% | Jan 16, 2024 |
| CVE-2023-39691 | An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request. | CRITICAL | 0.56% | Jan 16, 2024 |
| CVE-2023-6849 | kalcaddle kodbox app.php cover server-side request forgery | CRITICAL | 0.89% | Dec 16, 2023 |
| CVE-2023-6848 | kalcaddle kodbox index.class.php check command injection | CRITICAL | 2.35% | Dec 16, 2023 |
| CVE-2023-48028 | kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based o… | CRITICAL | 1.11% | Nov 17, 2023 |
| CVE-2023-45998 | kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS. | MEDIUM | 0.32% | Oct 23, 2023 |
| CVE-2023-3607 | kodbox WebConsole Plug-In webconsole.php.txt Execute os command injection | HIGH | 6.37% | Jul 10, 2023 |
| CVE-2023-29790 | kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue. | HIGH | 0.56% | May 12, 2023 |
| CVE-2023-29791 | kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information. | MEDIUM | 0.35% | May 11, 2023 |
Showing 1 to 14 of 14 CVEs