Codekop maintains a focused web application product where vulnerabilities cluster around authentication and authorization gaps alongside cross-site scripting issues in web-facing components. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codekop over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36347HIGH A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data. | Jun 30, 2023 | 7.5 | 46 | NO | YES |
CVE-2023-36348HIGH POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter. | Jun 23, 2023 | 8.8 | 39 | NO | YES |
CVE-2023-36346MEDIUM POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php. | Jun 23, 2023 | 6.1 | 34 | NO | YES |
CVE-2023-36345HIGH A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges. | Jun 23, 2023 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codekop.
Media articles that mention a CVE ID that affects a product developed by Codekop — matched by CVE ID, not by vendor name.