Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Coollabs

First CVE: Jan 24, 2025Active for: 1 yearTotal CVEs: 28
50.7
VTI Score
TOP TARGET

Coollabs maintains a focused containerization and application-deployment platform, Coolify, that simplifies infrastructure management for developers and small to medium-sized deployments. Despite a narrow product portfolio, the platform has gained prominence in the landscape, and its vulnerabilities skew toward serious outcomes with a meaningful share reaching critical severity. The recurring weakness classes—OS command injection, missing authorization, input validation flaws, sensitive information exposure, and output encoding failures—reflect the risks inherent in a system that bridges user-facing interfaces with underlying infrastructure automation and container orchestration. Defenders should prioritize patches for this vendor given the elevation in severity, as flaws at the infrastructure-orchestration layer can afford attackers broad lateral movement and system compromise. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
14.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 79% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Coollabs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2025
17 months ago
Most Recent CVE
Jan 5, 2026
200 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-34157CRITICAL
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges
Aug 27, 20259.034NONO
CVE-2025-64419HIGH
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are
Jan 5, 20268.833NONO
CVE-2025-66209HIGH
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit
Dec 23, 20258.833NONO
CVE-2025-34161HIGH
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, wit
Aug 27, 20258.833NONO
CVE-2025-64424HIGH
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vul
Jan 5, 20268.832NONO
CVE-2025-64420HIGH
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users
Jan 5, 20268.831NONO
CVE-2025-34159HIGH
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users,
Aug 27, 20258.831NONO
CVE-2025-22609CRITICAL
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authentica
Jan 24, 202510.031NONO
CVE-2025-66213HIGH
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit
Dec 23, 20258.830NONO
CVE-2025-66212HIGH
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit
Dec 23, 20258.830NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
21%
64%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (10.7%)
Network25 (89.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (71.4%)
Unknown0 (0.0%)
Required8 (28.6%)
Privileges Required
Low21 (75.0%)
High0 (0.0%)
None7 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Coollabs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Coollabs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Coollabs's Products

View all 2 CNAs →

Top CWEs