VendorsKodcloudkodexplorerall versions
Vulnerabilities

Kodcloud KodExplorer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2023-6851
kalcaddle KodExplorer ZIP Archive app.php unzipList code injection
Published 2023-12-16 · Modified
9.8EPSS 0.009
CVE-2023-6850
kalcaddle KodExplorer API Endpoint unrestricted upload
Published 2023-12-16 · Modified
9.8EPSS 0.008
CVE-2023-6852
kalcaddle KodExplorer app.php server-side request forgery
Published 2023-12-16 · Modified
9.8EPSS 0.008
CVE-2023-6853
kalcaddle KodExplorer app.php index server-side request forgery
Published 2023-12-16 · Modified
9.8EPSS 0.007
CVE-2022-4944
kalcaddle KodExplorer cross-site request forgery
Published 2023-04-22 · Modified
8.81 PoCEPSS 0.027
CVE-2022-46154
Arbitrary file access in KodExplorer
Published 2022-12-06 · Modified
8.6EPSS 0.009
CVE-2021-36646
A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.
Published 2023-09-06 · Modified
6.1EPSS 0.008
CVE-2023-37153
KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field.
Published 2023-07-10 · Modified
6.1EPSS 0.007
CVE-2023-49489
Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.
Published 2023-12-19 · Modified
6.1EPSS 0.007
CVE-2025-34504
KodExplorer 4.52 Open Redirect Vulnerability via User Login Endpoint
Published 2025-12-11 · Analyzed
6.1EPSS 0.003