ICEcoder records
6 published records for vendor icecoder.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2022-34026No exploit | ICEcoder v8.1 allows attackers to execute a directory traversal.icecoder · icecoder · CWE-22 | High7.5 | — | 1.7% | Sep 22, 2022 |
25Monitor | CVE-2024-41373No exploit | ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.icecoder · icecoder · CWE-22 | Medium6.3 | — | 0.4% | Jul 26, 2024 |
24Monitor | CVE-2024-41374No exploit | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.phpicecoder · icecoder · CWE-79 | Medium6.1 | — | 0.3% | Jul 26, 2024 |
24Monitor | CVE-2024-41375No exploit | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.phpicecoder · icecoder · CWE-79 | Medium6.1 | — | 0.3% | Jul 26, 2024 |
21Monitor | CVE-2021-32106No exploit | In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of theicecoder · icecoder · CWE-79 | Medium5.4 | — | 0.9% | Jun 8, 2021 |
19Monitor | CVE-2021-3862No exploit | Cross-site Scripting (XSS) - Reflected in icecoder/icecodericecoder · icecoder · CWE-79 | Medium4.8 | — | 0.7% | Jan 17, 2022 |
- CVE-2022-3402631Monitor
ICEcoder v8.1 allows attackers to execute a directory traversal.
HighCVSS 7.5No exploitEPSS 2%icecoder · icecoderSep 22, 2022
- CVE-2024-4137325Monitor
ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.
MediumCVSS 6.3No exploitEPSS 0%icecoder · icecoderJul 26, 2024
- CVE-2024-4137424Monitor
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
MediumCVSS 6.1No exploitEPSS 0%icecoder · icecoderJul 26, 2024
- CVE-2024-4137524Monitor
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
MediumCVSS 6.1No exploitEPSS 0%icecoder · icecoderJul 26, 2024
- CVE-2021-3210621Monitor
In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the
MediumCVSS 5.4No exploitEPSS 1%icecoder · icecoderJun 8, 2021
- CVE-2021-386219Monitor
Cross-site Scripting (XSS) - Reflected in icecoder/icecoder
MediumCVSS 4.8No exploitEPSS 1%icecoder · icecoderJan 17, 2022