Kodcloud Kodcloud

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Kodcloud product.

RSS Feeds for Kodcloud security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Kodcloud products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Kodcloud Sorted by Most Security Vulnerabilities since 2018

Kodcloud Kodexplorer14 vulnerabilities

Kodcloud Kodbox11 vulnerabilities

By the Year

In 2026 there have been 4 vulnerabilities in Kodcloud with an average score of 5.9 out of ten. Last year, in 2025 Kodcloud had 1 security vulnerability published. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 4 5.90
2025 1 0.00
2024 4 6.65
2023 15 8.06
2022 1 7.50

It may take a day or so for new Kodcloud vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Kodcloud Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-6571 Apr 19, 2026
Auth Bypass in KodExplorer 4.52 via group_role A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Kodexplorer
CVE-2026-6570 Apr 19, 2026
kodcloud KodExplorer <=4.52 initInstall Auth Bypass (path manipulation) A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Kodexplorer
CVE-2026-6569 Apr 19, 2026
kodcloud KodExplorer 4.52 Remote Improper Auth via fileGet Endpoint A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Kodexplorer
CVE-2026-6568 Apr 19, 2026
KodExplorer 4.52 PubShareHandler PT via share.class.php initShareOld A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Kodexplorer
CVE-2025-34504 Dec 11, 2025
KodExplorer 4.52 Open Redirect on login page via 'link' param KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.
Kodexplorer
CVE-2024-51037 Nov 15, 2024
Kodbox Password Reset Captcha Information Disclosure Vulnerability An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.
Kodbox
CVE-2023-52069 Jan 17, 2024
Kodbox v1.49.04 URL XSS via param kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.
Kodbox
CVE-2023-39691 Jan 16, 2024
kodbox <=1.43 arbitrary Admin account creation via crafted GET An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.
Kodbox
CVE-2023-52068 Jan 16, 2024
Kodbox v1.43 XSS via Operation & Login Logs kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
Kodbox
CVE-2023-49489 Dec 19, 2023
KodExplorer 4.51 XSS via APP_HOST in config/i18n/en/main.php Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.
Kodexplorer
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.