codologic
Web & CMS Pluginscommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting codologic.
- CVE-2020-22540Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.5.4
- CVE-2020-22539An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file.7.2
- CVE-2022-31854Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.7.2
- CVE-2020-25875A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered in...5.4
- CVE-2020-25876A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into...5.4
- CVE-2020-25879A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload ent...5.4
- CVE-2020-13873A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a leaked password-re...9.8
- CVE-2020-9007Codoforum 4.8.8 allows self-XSS via the title of a new topic.5.4
- CVE-2020-7050Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is ...5.4
- CVE-2020-7051Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeo...6.1
- CVE-2020-5842Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manag...6.1
- CVE-2020-5843Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.4.8
- CVE-2020-5306Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.4.8
- CVE-2020-5305Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.4.8
- CVE-2014-9261The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the pat...5.0