Codiad is a compact, web-based integrated development environment whose vulnerability profile concentrates in a single product and has attracted public exploit code. The recurring exposure centers on web-application input-handling and code-generation weaknesses, including cross-site scripting, code injection, cross-site request forgery, and sensitive information disclosure, reflecting the inherent risks of a browser-accessible editor. Vulnerabilities affecting this vendor skew toward serious outcomes; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codiad over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14009CRITICAL Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. | Jul 12, 2018 | 9.8 | 61 | NO | YES |
CVE-2019-19208CRITICAL Codiad Web IDE through 2.8.4 allows PHP Code injection. | Mar 16, 2020 | 9.8 | 51 | NO | YES |
CVE-2018-19423HIGH Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file. | Nov 21, 2018 | 7.2 | 43 | NO | YES |
CVE-2017-11366CRITICAL components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonst | Aug 21, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-20178HIGH ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/ | Feb 21, 2023 | 7.5 | 24 | NO | NO |
CVE-2020-14044HIGH ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin | Aug 24, 2020 | 7.2 | 24 | NO | NO |
CVE-2014-9581MEDIUM Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter. | Jan 8, 2015 | 5.0 | 23 | NO | YES |
CVE-2020-23355HIGH ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value | Jan 27, 2021 | 7.5 | 22 | NO | NO |
CVE-2020-14042MEDIUM ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization | Aug 25, 2020 | 6.1 | 22 | NO | NO |
CVE-2020-14043HIGH ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketpl | Aug 24, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codiad.
Media articles that mention a CVE ID that affects a product developed by Codiad — matched by CVE ID, not by vendor name.