Vulnerabilities > Kodcloud > Kodbox

DATE CVE VULNERABILITY TITLE RISK
2024-01-17 CVE-2023-52069 Cross-site Scripting vulnerability in Kodcloud Kodbox 1.49.04
kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.
network
low complexity
kodcloud CWE-79
5.4
2024-01-16 CVE-2023-39691 Unspecified vulnerability in Kodcloud Kodbox
An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.
network
low complexity
kodcloud
critical
9.8
2024-01-16 CVE-2023-52068 Cross-site Scripting vulnerability in Kodcloud Kodbox 1.43
kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
network
low complexity
kodcloud CWE-79
6.1
2023-12-16 CVE-2023-6849 Server-Side Request Forgery (SSRF) vulnerability in Kodcloud Kodbox
A vulnerability was found in kalcaddle kodbox up to 1.48.
network
low complexity
kodcloud CWE-918
critical
9.8
2023-12-16 CVE-2023-6848 Command Injection vulnerability in Kodcloud Kodbox
A vulnerability was found in kalcaddle kodbox up to 1.48.
network
low complexity
kodcloud CWE-77
critical
9.8
2023-11-18 CVE-2023-48028 Improper Restriction of Excessive Authentication Attempts vulnerability in Kodcloud Kodbox 1.46.01
kodbox 1.46.01 has a security flaw that enables user enumeration.
network
low complexity
kodcloud CWE-307
critical
9.8
2023-10-23 CVE-2023-45998 Cross-site Scripting vulnerability in Kodcloud Kodbox 1.44
kodbox 1.44 is vulnerable to Cross Site Scripting (XSS).
network
low complexity
kodcloud CWE-79
5.4
2023-07-10 CVE-2023-3607 OS Command Injection vulnerability in Kodcloud Kodbox 1.26
A vulnerability was found in kodbox 1.26.
low complexity
kodcloud CWE-78
8.0
2023-05-12 CVE-2023-29790 Unspecified vulnerability in Kodcloud Kodbox
kodbox 1.2.x through 1.3.7 has a Sensitive Information Leakage issue.
network
low complexity
kodcloud
7.5
2023-05-11 CVE-2023-29791 Cross-site Scripting vulnerability in Kodcloud Kodbox
kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information.
network
low complexity
kodcloud CWE-79
6.1