VendorsKodcloudkodboxall versions
Vulnerabilities

Kodcloud Kodbox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2023-6848
kalcaddle kodbox index.class.php check command injection
Published 2023-12-16 · Modified
9.8EPSS 0.023
CVE-2023-48028
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
Published 2023-11-17 · Modified
9.8EPSS 0.011
CVE-2023-6849
kalcaddle kodbox app.php cover server-side request forgery
Published 2023-12-16 · Modified
9.8EPSS 0.009
CVE-2023-39691
An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.
Published 2024-01-16 · Modified
9.8EPSS 0.006
CVE-2026-1066
kalcaddle kodbox Compression zip command injection
Published 2026-01-17 · Analyzed
8.8EPSS 0.056
CVE-2023-3607
kodbox WebConsole Plug-In webconsole.php.txt Execute os command injection
Published 2023-07-10 · Modified
8.0EPSS 0.064
CVE-2023-29790
kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.
Published 2023-05-12 · Modified
7.5EPSS 0.006
CVE-2025-10233
kalcaddle kodbox editor.class.php fileSave path traversal
Published 2025-09-10 · Analyzed
6.5EPSS 0.004
CVE-2023-29791
kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.
Published 2023-05-11 · Modified
6.1EPSS 0.004
CVE-2023-52068
kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
Published 2024-01-16 · Modified
6.1EPSS 0.003
CVE-2025-9414
kalcaddle kodbox Download from Link serverDownload server-side request forgery
Published 2025-08-25 · Analyzed
5.8EPSS 0.003
CVE-2023-45998
kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.
Published 2023-10-23 · Modified
5.4EPSS 0.003
CVE-2023-52069
kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.
Published 2024-01-17 · Modified
5.4EPSS 0.003
CVE-2024-51037
An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.
Published 2024-11-15 · Modified
5.3EPSS 0.003