Magicbug's vulnerability profile centers on a narrowly scoped portfolio around its CloudLog product, which appears to serve logging and data-management functions in enterprise environments. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, driven by the recurring presence of SQL injection weaknesses in the product's data-handling layer. Defenders should prioritize patching for this vendor given the severity and exploit-availability tendency; live exploitation status and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Magicbug over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48259HIGH Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign. | Oct 14, 2024 | 7.3 | 32 | NO | YES |
CVE-2024-44065CRITICAL Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter. | Dec 26, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-48255CRITICAL Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection. | Oct 14, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-48253CRITICAL Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection. | Oct 14, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-45999CRITICAL A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vuln | Oct 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-64084MEDIUM An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize t | Nov 14, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Magicbug.
Media articles that mention a CVE ID that affects a product developed by Magicbug — matched by CVE ID, not by vendor name.