Cobub's vulnerability profile centers on its Razor product, a web-based application where vulnerabilities skew toward serious outcomes and frequently acquire public exploit code. The recurring weakness classes span a characteristic set of web-application input-handling and authentication flaws: cross-site request forgery, cross-site scripting, SQL injection, improper authentication, and exposure of sensitive information, reflecting the common vulnerabilities endemic to server-side web applications. Defenders should treat this vendor's advisories as security-relevant and prioritize internet-exposed instances; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cobub over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8770MEDIUM Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, | Mar 18, 2018 | 5.3 | 71 | NO | YES |
CVE-2018-8056HIGH Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a direct request to /export.php. | Mar 11, 2018 | 7.5 | 41 | NO | YES |
CVE-2018-7745HIGH An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/installation/createuserinfo requests, resulting in account creat | Mar 7, 2018 | 7.5 | 41 | NO | YES |
CVE-2018-7746HIGH An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example, with a crafted channel name, | Mar 7, 2018 | 8.8 | 39 | NO | YES |
CVE-2019-10276CRITICAL Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type. | Mar 29, 2019 | 9.8 | 31 | NO | NO |
CVE-2024-28421CRITICAL SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php | Mar 25, 2024 | 9.8 | 26 | NO | NO |
CVE-2018-7720HIGH A cross-site request forgery (CSRF) vulnerability exists in Western Bridge Cobub Razor 0.7.2 via /index.php?/user/createNewUser/, resulting in account creation. | Mar 7, 2018 | 8.8 | 26 | NO | NO |
CVE-2022-36747MEDIUM Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel(). | Aug 30, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cobub.
Media articles that mention a CVE ID that affects a product developed by Cobub — matched by CVE ID, not by vendor name.