Coolify
Vendor:
First CVE: Jan 24, 2025 · Active for 1 year
28
Total CVEs
More Total CVEs than 96% of tracked products
14.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Coolify over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2025
17 months ago
Most Recent CVE
Jan 5, 2026
200 days ago
CVE Severity & Scoring
Coolify28 CVEs
21%
64%
14%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (10.7%)
Network25 (89.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (71.4%)
Unknown0 (0.0%)
Required8 (28.6%)
Privileges Required
Low21 (75.0%)
High0 (0.0%)
None7 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-34157CRITICAL Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges | Aug 27, 2025 | 9.0 | 34 | NO | NO |
CVE-2025-64419HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are | Jan 5, 2026 | 8.8 | 33 | NO | NO |
CVE-2025-66209HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit | Dec 23, 2025 | 8.8 | 33 | NO | NO |
CVE-2025-34161HIGH Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, wit | Aug 27, 2025 | 8.8 | 33 | NO | NO |
CVE-2025-64424HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vul | Jan 5, 2026 | 8.8 | 32 | NO | NO |
CVE-2025-64420HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users | Jan 5, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-34159HIGH Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, | Aug 27, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-22609CRITICAL Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authentica | Jan 24, 2025 | 10.0 | 31 | NO | NO |
CVE-2025-66213HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit | Dec 23, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-66212HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit | Dec 23, 2025 | 8.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Coolify
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.0 | 28 | 8.3 | 1.3% | 0 | 0 |