Codefuture develops image-hosting and content-delivery software where the observed vulnerability footprint centers on access-control and input-handling issues, particularly improper file and directory permissions alongside cross-site scripting in web-generation contexts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codefuture over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25709CRITICAL CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attacker | Apr 12, 2026 | 9.8 | 32 | NO | NO |
CVE-2011-4572MEDIUM Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to injec | Nov 29, 2011 | 4.3 | 24 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codefuture.
Media articles that mention a CVE ID that affects a product developed by Codefuture — matched by CVE ID, not by vendor name.