VulnSea

ICEcoder has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 8.8 (high).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.8
Publish → KEV
Last 90 days
3 prev 0

Products

  • icecoder/icecoder 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

ICEcoder vulnerabilities

CVEs affecting ICEcoder, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-64838High· 8.3PoC
1w ago

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequenc…

MidnightICEcoder · icecoder/icecoderEPSS 0.49%via NVD
CVE-2026-64837High· 8.8
1w ago

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters i…

TwilightICEcoder · icecoder/icecoderEPSS 0.54%via NVD
CVE-2026-64836High· 8.8
1w ago

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, whi…

TwilightICEcoder · icecoder/icecoderEPSS 0.45%via NVD
ICEcoder vulnerabilities (CVEs) · VulnSea