Skip to content
Noroxi

magicbug records

6 published records for vendor magicbug.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 24
  2. 25

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

6 records
  • Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.

    CriticalCVSS 9.8No exploitEPSS 0%

    magicbug · cloudlogOct 14, 2024

  • Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.

    CriticalCVSS 9.8No exploitEPSS 0%

    magicbug · cloudlogOct 14, 2024

  • Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults paramet

    CriticalCVSS 9.8No exploitEPSS 0%

    magicbug · cloudlogDec 26, 2025

  • A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /app

    CriticalCVSS 9.8No exploitEPSS 0%

    magicbug · cloudlogOct 1, 2024

  • Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.

    HighCVSS 7.3Proof of conceptEPSS 1%

    magicbug · cloudlogOct 14, 2024

  • An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier.

    MediumCVSS 5.4No exploitEPSS 0%

    magicbug · cloudlogNov 14, 2025