Coolify

Vendor:

First CVE: Jan 24, 2025 · Active for 1 year

28
Total CVEs
More Total CVEs than 96% of tracked products
14.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Coolify over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2025
17 months ago
Most Recent CVE
Jan 5, 2026
200 days ago

CVE Severity & Scoring

Coolify28 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local3 (10.7%)
Network25 (89.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (71.4%)
Unknown0 (0.0%)
Required8 (28.6%)
Privileges Required
Low21 (75.0%)
High0 (0.0%)
None7 (25.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges
Aug 27, 20259.034NONO
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are
Jan 5, 20268.833NONO
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit
Dec 23, 20258.833NONO
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, wit
Aug 27, 20258.833NONO
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vul
Jan 5, 20268.832NONO
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users
Jan 5, 20268.831NONO
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users,
Aug 27, 20258.831NONO
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authentica
Jan 24, 202510.031NONO
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit
Dec 23, 20258.830NONO
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit
Dec 23, 20258.830NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Coolify

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.0288.31.3%00