Skip to content
Noroxi

codologic records

16 published records for vendor codologic.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

16 records
  • A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authenti

    CriticalCVSS 9.8No exploitEPSS 5%

    codologic · codoforumMay 12, 2021

  • Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

    HighCVSS 7.2Proof of conceptEPSS 32%

    codologic · codoforumJul 7, 2022

  • An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploadi

    HighCVSS 7.2No exploitEPSS 1%

    codologic · codoforumApr 15, 2024

  • CVE-2020-5842
    25Monitor

    Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI.

    MediumCVSS 6.1Proof of conceptEPSS 2%

    codologic · codoforumJan 7, 2020

  • CVE-2020-7051
    24Monitor

    Codologic Codoforum through 4.8.4 allows stored XSS in the login area.

    MediumCVSS 6.1No exploitEPSS 1%

    codologic · codoforumFeb 13, 2020

  • CVE-2014-9261
    23Monitor

    The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attack

    MediumCVSS 5.0Proof of conceptEPSS 9%

    codologic · codoforumMar 23, 2015

  • CVE-2020-7050
    21Monitor

    Codologic Codoforum through 4.8.4 allows a DOM-based XSS.

    MediumCVSS 5.4No exploitEPSS 1%

    codologic · codoforumFeb 15, 2020

  • CVE-2020-9007
    21Monitor

    Codoforum 4.8.8 allows self-XSS via the title of a new topic.

    MediumCVSS 5.4No exploitEPSS 1%

    codologic · codoforumFeb 16, 2020

  • A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arb

    MediumCVSS 5.4No exploitEPSS 1%

    codologic · codoforumJul 9, 2021

  • A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execut

    MediumCVSS 5.4No exploitEPSS 0%

    codologic · codoforumJul 9, 2021

  • A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbit

    MediumCVSS 5.4No exploitEPSS 0%

    codologic · codoforumJul 9, 2021

  • Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive informati

    MediumCVSS 5.4No exploitEPSS 0%

    codologic · codoforumApr 15, 2024

  • CVE-2020-5306
    19Monitor

    Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.

    MediumCVSS 4.8No exploitEPSS 1%

    codologic · codoforumJan 5, 2020

  • CVE-2020-5305
    19Monitor

    Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.

    MediumCVSS 4.8No exploitEPSS 1%

    codologic · codoforumJan 5, 2020

  • CVE-2020-5843
    19Monitor

    Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.

    MediumCVSS 4.8No exploitEPSS 1%

    codologic · codoforumJan 7, 2020

  • CVE-2013-5952
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow re

    MediumCVSS 4.3No exploitEPSS 2%

    joomla · joomla\!Mar 19, 2014