codiad records
14 published records for vendor codiad.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
50Plan | CVE-2018-14009Proof of concept | Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.codiad · codiad · CWE-20 | Critical9.8 | — | 38.0% | Jul 12, 2018 |
45Plan | CVE-2019-19208Proof of concept | Codiad Web IDE through 2.8.4 allows PHP Code injection.codiad · codiad · CWE-94 | Critical9.8 | — | 19.2% | Mar 16, 2020 |
41Plan | CVE-2017-11366Proof of concept | components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be codiad · codiad · CWE-78 | Critical9.8 | — | 7.5% | Aug 20, 2017 |
35Monitor | CVE-2020-14043No exploit | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later.codiad · codiad · CWE-352 | High8.8 | — | 1.5% | Aug 24, 2020 |
33Monitor | CVE-2018-19423Proof of concept | Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.codiad · codiad · CWE-434 | High7.2 | — | 18.1% | Nov 21, 2018 |
30Monitor | CVE-2020-23355No exploit | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authenticacodiad · codiad | High7.5 | — | 1.0% | Jan 27, 2021 |
30Monitor | CVE-2017-1000125No exploit | Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.codiad · codiad · CWE-732 | High7.5 | — | 0.9% | Nov 17, 2017 |
30Monitor | CVE-2017-20178No exploit | Codiad process.php saveJSON information disclosurecodiad · codiad · CWE-200 | High7.5 | — | 0.7% | Feb 21, 2023 |
29Monitor | CVE-2020-14044No exploit | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later.codiad · codiad · CWE-918 | High7.2 | — | 3.2% | Aug 24, 2020 |
24Monitor | CVE-2020-14042No exploit | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later.codiad · codiad · CWE-79 | Medium6.1 | — | 1.2% | Aug 25, 2020 |
21Monitor | CVE-2014-9581Proof of concept | Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files viacodiad · codiad · CWE-22 | Medium5.0 | — | 3.6% | Jan 8, 2015 |
21Monitor | CVE-2024-26557No exploit | Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.codiad · codiad · CWE-79 | Medium5.4 | — | 0.3% | Mar 21, 2024 |
18Monitor | CVE-2013-7257No exploit | Cross-site scripting (XSS) vulnerability in Codiad 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the Project Namecodiad · codiad · CWE-79 | Medium4.3 | — | 1.9% | Jan 3, 2014 |
17Monitor | CVE-2014-9582Proof of concept | Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary wecodiad · codiad · CWE-79 | Medium4.3 | — | 1.5% | Jan 8, 2015 |
- CVE-2018-1400950Plan
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
CriticalCVSS 9.8Proof of conceptEPSS 38%codiad · codiadJul 12, 2018
- CVE-2019-1920845Plan
Codiad Web IDE through 2.8.4 allows PHP Code injection.
CriticalCVSS 9.8Proof of conceptEPSS 19%codiad · codiadMar 16, 2020
- CVE-2017-1136641Plan
components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be
CriticalCVSS 9.8Proof of conceptEPSS 8%codiad · codiadAug 20, 2017
- CVE-2020-1404335Monitor
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later.
HighCVSS 8.8No exploitEPSS 2%codiad · codiadAug 24, 2020
- CVE-2018-1942333Monitor
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
HighCVSS 7.2Proof of conceptEPSS 18%codiad · codiadNov 21, 2018
- CVE-2020-2335530Monitor
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentica
HighCVSS 7.5No exploitEPSS 1%codiad · codiadJan 27, 2021
- CVE-2017-100012530Monitor
Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.
HighCVSS 7.5No exploitEPSS 1%codiad · codiadNov 17, 2017
- CVE-2017-2017830Monitor
Codiad process.php saveJSON information disclosure
HighCVSS 7.5No exploitEPSS 1%codiad · codiadFeb 21, 2023
- CVE-2020-1404429Monitor
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later.
HighCVSS 7.2No exploitEPSS 3%codiad · codiadAug 24, 2020
- CVE-2020-1404224Monitor
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later.
MediumCVSS 6.1No exploitEPSS 1%codiad · codiadAug 25, 2020
- CVE-2014-958121Monitor
Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via
MediumCVSS 5.0Proof of conceptEPSS 4%codiad · codiadJan 8, 2015
- CVE-2024-2655721Monitor
Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.
MediumCVSS 5.4No exploitEPSS 0%codiad · codiadMar 21, 2024
- CVE-2013-725718Monitor
Cross-site scripting (XSS) vulnerability in Codiad 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the Project Name
MediumCVSS 4.3No exploitEPSS 2%codiad · codiadJan 3, 2014
- CVE-2014-958217Monitor
Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary we
MediumCVSS 4.3Proof of conceptEPSS 1%codiad · codiadJan 8, 2015