Skip to main content

Vendor archive

codologic CVEs

Beta · best-effort

16 CVEs tagged to vendor codologic1 Critical, 2 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2020-22540

Published Apr 15, 2024

Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-22539

Published Apr 15, 2024

An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31854

Published Jul 7, 2022

Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25879

Published Jul 9, 2021

A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25876

Published Jul 9, 2021

A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted pa…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25875

Published Jul 9, 2021

A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13873

Published May 12, 2021

A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7050

Published Feb 15, 2020

Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7051

Published Feb 13, 2020

Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impac…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5842

Published Jan 7, 2020

Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.ph…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5843

Published Jan 7, 2020

Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5306

Published Jan 5, 2020

Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5305

Published Jan 5, 2020

Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9261

Published Mar 23, 2015

The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5952

Published Mar 19, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1