« Volver al listado

Kodcloud

Kodcloud Kodbox: vulnerabilidades y CVE

Kodcloud Kodbox tiene 27 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE27
Últimos 12 meses13
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-18721Baja (2.1)0.43%—4 ago 2026
A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO API Login. The manipulation of the argument callbackUrl…
CVE-2026-18720Media (5.5)0.48%—4 ago 2026
A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to…
CVE-2026-8753Baja (2.1)2.4%—17 may 2026
A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component…
CVE-2026-5618Baja (2.9)0.40%—6 abr 2026
A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side…
CVE-2026-4831Baja (2.9)0.57%—26 mar 2026
A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler.…
CVE-2026-4830Baja (2.9)0.40%—26 mar 2026
A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to…
CVE-2026-4592Baja (2.9)0.55%—23 mar 2026
A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of the component…
CVE-2026-4591Baja (2)3.4%—23 mar 2026
A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/source-code/plugins/fileThumb/app.php of the component fileThumb Endpoint. Executing a manipulation can…
CVE-2026-4590Baja (1.3)0.20%—23 mar 2026
A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /workspace/source-code/plugins/oauth/controller/bind/index.class.php of the component loginSubmit…
CVE-2026-4589Baja (2.1)0.35%—23 mar 2026
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint.…
CVE-2026-4588Baja (2.9)0.42%—23 mar 2026
A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-level API key Handler.…
CVE-2026-2560Baja (2.1)2.5%—16 feb 2026
A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such…
CVE-2026-1066Baja (2.1)5.6%—17 ene 2026
A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Compression Handler. The manipulation results in command…
CVE-2025-11016Baja (2.1)0.46%—26 sept 2025
A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileOut of the file app/controller/explorer/index.class.php. Such manipulation of the argument path…
CVE-2025-10233Baja (2.1)0.46%—10 sept 2025
A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path leads to path…
CVE-2025-9414Baja (2)0.30%—25 ago 2025
A vulnerability was found in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the file /?explorer/upload/serverDownload of the component Download from Link Handler. Performing…
CVE-2024-51037Media (5.3)0.28%—15 nov 2024
An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.
CVE-2023-52069Media (5.4)0.29%—17 ene 2024
kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.
CVE-2023-52068Media (6.1)0.31%—16 ene 2024
kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
CVE-2023-39691Crítica (9.8)0.56%—16 ene 2024
An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.
CVE-2023-6849Crítica (9.8)0.89%—16 dic 2023
A vulnerability was found in kalcaddle kodbox up to 1.48. It has been rated as critical. Affected by this issue is the function cover of the file plugins/fileThumb/app.php. The manipulation of the argument path leads to…
CVE-2023-6848Crítica (9.8)2.3%—16 dic 2023
A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerability is the function check of the file plugins/officeViewer/controller/libreOffice/index.class.php.…
CVE-2023-48028Crítica (9.8)1.1%—18 nov 2023
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for…
CVE-2023-45998Media (5.4)0.32%—23 oct 2023
kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.
CVE-2023-3607Alta (8)6.4%—10 jul 2023
A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Execute of the file webconsole.php.txt of the component WebConsole Plug-In. The manipulation leads to…
CVE-2023-29790Alta (7.5)0.56%—12 may 2023
kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.
CVE-2023-29791Media (6.1)0.35%—11 may 2023
kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.

Otros productos de Kodcloud