Kodcloud
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Kodcloud product.
RSS Feeds for Kodcloud security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Kodcloud products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Kodcloud Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 4 vulnerabilities in Kodcloud with an average score of 5.9 out of ten. Last year, in 2025 Kodcloud had 1 security vulnerability published. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 5.90 |
| 2025 | 1 | 0.00 |
| 2024 | 4 | 6.65 |
| 2023 | 15 | 8.06 |
| 2022 | 1 | 7.50 |
It may take a day or so for new Kodcloud vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Kodcloud Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-6571 | Apr 19, 2026 |
Auth Bypass in KodExplorer 4.52 via group_roleA weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. |
|
| CVE-2026-6570 | Apr 19, 2026 |
kodcloud KodExplorer <=4.52 initInstall Auth Bypass (path manipulation)A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. |
|
| CVE-2026-6569 | Apr 19, 2026 |
kodcloud KodExplorer 4.52 Remote Improper Auth via fileGet EndpointA vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. |
|
| CVE-2026-6568 | Apr 19, 2026 |
KodExplorer 4.52 PubShareHandler PT via share.class.php initShareOldA vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. |
|
| CVE-2025-34504 | Dec 11, 2025 |
KodExplorer 4.52 Open Redirect on login page via 'link' paramKodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication. |
|
| CVE-2024-51037 | Nov 15, 2024 |
Kodbox Password Reset Captcha Information Disclosure VulnerabilityAn issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function. |
|
| CVE-2023-52069 | Jan 17, 2024 |
Kodbox v1.49.04 URL XSS via paramkodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter. |
|
| CVE-2023-39691 | Jan 16, 2024 |
kodbox <=1.43 arbitrary Admin account creation via crafted GETAn issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request. |
|
| CVE-2023-52068 | Jan 16, 2024 |
Kodbox v1.43 XSS via Operation & Login Logskodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs. |
|
| CVE-2023-49489 | Dec 19, 2023 |
KodExplorer 4.51 XSS via APP_HOST in config/i18n/en/main.phpReflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php. |
|