Pgyer is the vendor behind CodeFever, a code hosting and collaboration platform, with a sparse vulnerability footprint centered on application-layer code and command execution handling. The observed weaknesses cluster around code injection and OS command injection, reflecting input-validation and command-construction risks inherent to development tooling that processes user-supplied code and build directives. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pgyer over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44080CRITICAL An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component. | Sep 27, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-26817HIGH codefever before 2023.2.7-commit-b1c2e7f was discovered to contain a remote code execution (RCE) vulnerability via the component /controllers/api/user.php. | Apr 7, 2023 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pgyer.
Media articles that mention a CVE ID that affects a product developed by Pgyer — matched by CVE ID, not by vendor name.