CVE-2025-59158High· 8.0▾ TwilightCoolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project cre…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g., member role) can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator later attempts to delete the project or its associated resource, the payload automatically executes in the admin’s browser context. Version 4.0.0-beta.420.7 contains a patch for the issue.
coolify < 4.0.0coolify = 4.0.0Upgrade past the affected range:
coolify 4.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-34157Critical· 9.0Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow
CVE-2026-12048Critical· 9.3Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths
CVE-2026-12047Low· 3.5HTML injection in pgAdmin 4's cloud deployment module
CVE-2025-64425High· 8.1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases
CVE-2025-64422Medium· 4.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases
CVE-2025-64423High· 8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases