VulnSea

icecoder/icecoder vulnerabilities

CVEs whose affected-version data names the icecoder/icecoder package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-64838High· 8.3PoC
1w ago

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequenc…

MidnightICEcoder · icecoder/icecoderEPSS 0.49%via NVD
CVE-2026-64837High· 8.8
1w ago

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters i…

TwilightICEcoder · icecoder/icecoderEPSS 0.54%via NVD
CVE-2026-64836High· 8.8
1w ago

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, whi…

TwilightICEcoder · icecoder/icecoderEPSS 0.45%via NVD
icecoder/icecoder vulnerabilities (CVEs) · VulnSea