Product
codologic codoforum
16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-22540
CVE-2020-22539
CVE-2022-31854
CVE-2020-25879
CVE-2020-25876
CVE-2020-25875
CVE-2020-13873
CVE-2020-21845
CVE-2020-9007
CVE-2020-7050
CVE-2020-7051
CVE-2020-5842
CVE-2020-5843
CVE-2020-5306
CVE-2020-5305
CVE-2014-9261
all versions
Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive
all versions
An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code v
all versions
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.
all versions
A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers
all versions
A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to exe
all versions
A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to e
< 4.9
A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pr
all versions
Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.'
all versions
Codoforum 4.8.8 allows self-XSS via the title of a new topic.
<= 4.8.4
Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a pol
<= 4.8.4
Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because
all versions
Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payloa
all versions
Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.
all versions
Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.
all versions
Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.
all versions
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows rem