codologic records
16 published records for vendor codologic.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-13873No exploit | A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authenticodologic · codoforum · CWE-89 | Critical9.8 | — | 4.9% | May 12, 2021 |
38Monitor | CVE-2022-31854Proof of concept | Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.codologic · codoforum · CWE-434 | High7.2 | — | 32.5% | Jul 7, 2022 |
28Monitor | CVE-2020-22539No exploit | An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploadicodologic · codoforum · CWE-434 | High7.2 | — | 0.9% | Apr 15, 2024 |
25Monitor | CVE-2020-5842Proof of concept | Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI.codologic · codoforum · CWE-79 | Medium6.1 | — | 1.8% | Jan 7, 2020 |
24Monitor | CVE-2020-7051No exploit | Codologic Codoforum through 4.8.4 allows stored XSS in the login area.codologic · codoforum · CWE-79 | Medium6.1 | — | 0.8% | Feb 13, 2020 |
23Monitor | CVE-2014-9261Proof of concept | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackcodologic · codoforum · CWE-22 | Medium5.0 | — | 9.0% | Mar 23, 2015 |
21Monitor | CVE-2020-7050No exploit | Codologic Codoforum through 4.8.4 allows a DOM-based XSS.codologic · codoforum · CWE-79 | Medium5.4 | — | 0.5% | Feb 15, 2020 |
21Monitor | CVE-2020-9007No exploit | Codoforum 4.8.8 allows self-XSS via the title of a new topic.codologic · codoforum · CWE-79 | Medium5.4 | — | 0.5% | Feb 16, 2020 |
21Monitor | CVE-2020-25875No exploit | A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbcodologic · codoforum · CWE-79 | Medium5.4 | — | 0.5% | Jul 9, 2021 |
21Monitor | CVE-2020-25879No exploit | A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to executcodologic · codoforum · CWE-79 | Medium5.4 | — | 0.5% | Jul 9, 2021 |
21Monitor | CVE-2020-25876No exploit | A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitcodologic · codoforum · CWE-79 | Medium5.4 | — | 0.5% | Jul 9, 2021 |
21Monitor | CVE-2020-22540No exploit | Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive informaticodologic · codoforum · CWE-79 | Medium5.4 | — | 0.4% | Apr 15, 2024 |
19Monitor | CVE-2020-5306No exploit | Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.codologic · codoforum · CWE-79 | Medium4.8 | — | 1.1% | Jan 5, 2020 |
19Monitor | CVE-2020-5305No exploit | Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.codologic · codoforum · CWE-79 | Medium4.8 | — | 0.6% | Jan 5, 2020 |
19Monitor | CVE-2020-5843No exploit | Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.codologic · codoforum · CWE-79 | Medium4.8 | — | 0.5% | Jan 7, 2020 |
18Monitor | CVE-2013-5952No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow rejoomla · joomla\! · CWE-79 | Medium4.3 | — | 1.9% | Mar 19, 2014 |
- CVE-2020-1387340Plan
A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authenti
CriticalCVSS 9.8No exploitEPSS 5%codologic · codoforumMay 12, 2021
- CVE-2022-3185438Monitor
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.
HighCVSS 7.2Proof of conceptEPSS 32%codologic · codoforumJul 7, 2022
- CVE-2020-2253928Monitor
An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploadi
HighCVSS 7.2No exploitEPSS 1%codologic · codoforumApr 15, 2024
- CVE-2020-584225Monitor
Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI.
MediumCVSS 6.1Proof of conceptEPSS 2%codologic · codoforumJan 7, 2020
- CVE-2020-705124Monitor
Codologic Codoforum through 4.8.4 allows stored XSS in the login area.
MediumCVSS 6.1No exploitEPSS 1%codologic · codoforumFeb 13, 2020
- CVE-2014-926123Monitor
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attack
MediumCVSS 5.0Proof of conceptEPSS 9%codologic · codoforumMar 23, 2015
- CVE-2020-705021Monitor
Codologic Codoforum through 4.8.4 allows a DOM-based XSS.
MediumCVSS 5.4No exploitEPSS 1%codologic · codoforumFeb 15, 2020
- CVE-2020-900721Monitor
Codoforum 4.8.8 allows self-XSS via the title of a new topic.
MediumCVSS 5.4No exploitEPSS 1%codologic · codoforumFeb 16, 2020
- CVE-2020-2587521Monitor
A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arb
MediumCVSS 5.4No exploitEPSS 1%codologic · codoforumJul 9, 2021
- CVE-2020-2587921Monitor
A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execut
MediumCVSS 5.4No exploitEPSS 0%codologic · codoforumJul 9, 2021
- CVE-2020-2587621Monitor
A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbit
MediumCVSS 5.4No exploitEPSS 0%codologic · codoforumJul 9, 2021
- CVE-2020-2254021Monitor
Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive informati
MediumCVSS 5.4No exploitEPSS 0%codologic · codoforumApr 15, 2024
- CVE-2020-530619Monitor
Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.
MediumCVSS 4.8No exploitEPSS 1%codologic · codoforumJan 5, 2020
- CVE-2020-530519Monitor
Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.
MediumCVSS 4.8No exploitEPSS 1%codologic · codoforumJan 5, 2020
- CVE-2020-584319Monitor
Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.
MediumCVSS 4.8No exploitEPSS 1%codologic · codoforumJan 7, 2020
- CVE-2013-595218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow re
MediumCVSS 4.3No exploitEPSS 2%joomla · joomla\!Mar 19, 2014