Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Codoforum MEDIUM 5.4
CVE-2020-22540

Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via cr…

No fix yet
Fix from $1,600 2024-04-15
Codoforum HIGH 7.2
CVE-2020-22539

An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a craf…

No fix yet
Fix from $1,950 2024-04-15
Codoforum HIGH 7.2
CVE-2022-31854EPSS 32%

Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

No fix yet
Fix from $1,950 2022-07-07
Codoforum MEDIUM 5.4
CVE-2020-25875

A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary we…

No fix yet
Fix from $1,600 2021-07-09
Codoforum MEDIUM 5.4
CVE-2020-25876

A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web …

No fix yet
Fix from $1,600 2021-07-09
Codoforum MEDIUM 5.4
CVE-2020-25879

A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitra…

No fix yet
Fix from $1,600 2021-07-09
Codoforum CRITICAL 9.8
CVE-2020-13873

A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) t…

Fix: 4.9+
Fix from $2,300 2021-05-12
Codoforum MEDIUM 5.4
CVE-2020-9007

Codoforum 4.8.8 allows self-XSS via the title of a new topic.

No fix yet
Fix from $1,600 2020-02-16
Codoforum MEDIUM 5.4
CVE-2020-7050

Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatic…

Fix: after 4.8.4
Fix from $1,600 2020-02-15
Codoforum MEDIUM 6.1
CVE-2020-7051

Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lac…

Fix: after 4.8.4
Fix from $1,600 2020-02-13
Codoforum MEDIUM 6.1
CVE-2020-5842

Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, …

No fix yet
Fix from $1,600 2020-01-07
Codoforum MEDIUM 5.0
CVE-2014-9261EPSS 9%

The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to re…

No fix yet
Fix from $1,600 2015-03-23