vciy

CVEs we hold for Coder

Records whose assigning authority named Coder as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9009Crawlomatic Multipage Scraper Post Generator <= 2.7.2 - Authenticated (Author+) Remote Code Execution via…CodeRevolution Crawlomatic Multipage Scraper Post Generator
CVE-2026-82460Cloud Commander before 19.20.2 Directory Traversal via REST and Markdowncoderaiser cloudcmd
CVE-2026-82289Gitingest Prefix-Based Git Host Check Enables Request Forgery and Token Disclosurecoderamp-labs gitingest
CVE-2026-6709Coinbase Commerce for Contact Form 7 <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) API Key…coderpress Coinbase Commerce for Contact Form 7
CVE-2026-63443Coder: Workspace agent API insecure redirect handling allowed cross-agent file read and writecoder
CVE-2026-57719WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerabilityCodeRevolution Aimogen Pro
CVE-2026-55438Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofingcoder
CVE-2026-55437Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine componentcoder
CVE-2026-55436Coder's AI Bridge Proxy skips TLS certificate verification in default configurationcoder
CVE-2026-55435Suspended Coder users retain access to AI Bridge LLM proxy endpointscoder
CVE-2026-55434Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpointscoder
CVE-2026-55433Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containerscoder
CVE-2026-55432Coder's sub-agent app registration bypasses template port-sharing policy enforcementcoder
CVE-2026-55431Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace appscoder
CVE-2026-55430Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data accesscoder
CVE-2026-55429Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app IDcoder
CVE-2026-55428Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinatorcoder
CVE-2026-55427Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`coder
CVE-2026-55079Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of servicecoder
CVE-2026-55078Coder: Zip upload decompression lacks aggregate size limit, enabling denial of servicecoder
CVE-2026-55077Coder: User-admin role can reset owner account passwordcoder
CVE-2026-55076Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linkingcoder
CVE-2026-55075Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypasscoder
CVE-2026-46354Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theftcoder
CVE-2026-45796Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpointcoder
CVE-2026-44454Coder vulnerable to workspace auto-creation via crafted URL parameters without user consentcoder
CVE-2026-4038Aimogen Pro <= 2.7.5 - Unauthenticated Privilege Escalation via Arbitrary Function CallCodeRevolution Aimogen Pro - All-in-One AI Content Writer…
CVE-2026-39448WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control vulnerabilityCoderPress NOWPayments for WooCommerce
CVE-2026-35454Code Extension Marketplace has a Zip Slip Path Traversalcoder code-marketplace
CVE-2026-25396WordPress Commerce Coinbase For WooCommerce plugin <= 1.6.6 - Broken Access Control vulnerabilityCoderPress Commerce Coinbase For WooCommerce
CVE-2026-15982Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege…CodeRevolution Aimogen Pro - All-in-One AI Content Writer…
CVE-2025-66411Coder logged sensitive objects unsanitizedcoder
CVE-2025-6206Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.5.0 - Authenticated (Subscriber+) Arbitrary File UploadCodeRevolution Aiomatic - Automatic AI Content Writer &…
CVE-2025-59956AgentAPI exposed user chat history via a DNS rebinding attackcoder agentapi
CVE-2025-59553WordPress Custom iFrame for Elementor Plugin <= 1.0.13 - Cross Site Scripting (XSS) VulnerabilityCoderz Studio Custom iFrame for Elementor
CVE-2025-58437Coder's privilege escalation vulnerability could lead to a cross workspace compromisecoder
CVE-2025-49312WordPress Echo RSS Feed Post Generator Plugin for WordPress plugin <= 5.4.8.1 - Reflected Cross Site Scripting (XSS)…CodeRevolution Echo RSS Feed Post Generator Plugin for…
CVE-2025-49294WordPress Crawlomatic Multisite Scraper Post Generator plugin <= 2.6.8.2 - Sensitive Data Exposure via Log Exposure…CodeRevolution Crawlomatic Multisite Scraper Post Generator
CVE-2025-49293WordPress Crawlomatic Multisite Scraper Post Generator plugin <= 2.6.8.2 - Broken Access Control VulnerabilityCodeRevolution Crawlomatic Multisite Scraper Post Generator
CVE-2025-47269code-server session cookie can be extracted by having user visit specially crafted proxy URLcoder code-server
CVE-2025-4391Echo RSS Feed Post Generator <= 5.4.8.1 - Unauthenticated Arbitrary File UploadCodeRevolution Echo RSS Feed Post Generator
CVE-2025-4389Crawlomatic Multipage Scraper Post Generator <= 2.6.8.1 - Unauthenticated Arbitrary File UploadCodeRevolution Crawlomatic Multipage Scraper Post Generator
CVE-2025-30620WordPress WP Odoo Form Integrator plugin <=1.1.0 - CSRF to Stored XSS vulnerabilitycoderscom WP Odoo Form Integrator
CVE-2025-12398Product Table for WooCommerce <= 5.0.8 - Reflected Cross-Site Scriptingcodersaiful Product Table for WooCommerce
CVE-2024-9265Echo RSS Feed Post Generator <= 5.4.6 - Unauthenticated Privilege EscalationCodeRevolution Echo RSS Feed Post Generator
CVE-2024-6532Sheet to Table Live Sync for Google Sheet <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via…codersaiful Sheet to Table Live Sync for Google Sheet
CVE-2024-5969AIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email SendingCodeRevolution Aiomatic - Automatic AI Content Writer &…
CVE-2024-51681WordPress WP Pocket URLs plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerabilityCodeRevolution WP Pocket URLs
CVE-2024-4866UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere…codersaiful UltraAddons for Elementor
CVE-2024-34435WordPress Aiomatic plugin <= 1.9.3 - Broken Access Control vulnerabilityCodeRevolution Aiomatic
CVE-2024-31290WordPress Demo My WordPress plugin <= 1.0.9.1 - Unauthenticated Privilege Escalation vulnerabilityCodeRevolution Demo My WordPress
CVE-2024-27918Coder's OIDC authentication allows email with partially matching domain to registercoder
CVE-2024-25917WordPress WP Setup Wizard plugin <= 1.0.8.1 - Auth. Full Database Download VulnerabilityCodeRevolution WP Setup Wizard
CVE-2024-13882Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 - Missing Authorization to Authenticated…CodeRevolution Aiomatic - Automatic AI Content Writer &…
CVE-2024-13816Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated…CodeRevolution Aiomatic - Automatic AI Content Writer &…
CVE-2024-12615Passwords Manager <= 1.4.8 - Authenticated (Subscriber+) SQL Injectioncoder426 Passwords Manager
CVE-2024-12614Passwords Manager <= 1.4.8 - Missing Authorization to Authenticated (Subscriber+) Add Password + Update Encryption Keycoder426 Passwords Manager
CVE-2024-12613Passwords Manager <= 1.4.8 - Unauthenticated SQL Injectioncoder426 Passwords Manager
CVE-2024-12448Posts and Products Views for WooCommerce <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scriptingcoderpress Posts and Products Views for WooCommerce
CVE-2024-10813Product Table for WooCommerce by CodeAstrology (wooproducttable.com) <= 3.5.1 - Information Exposurecodersaiful Product Table for WooCommerce
CVE-2024-10696UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere…codersaiful UltraAddons for Elementor
CVE-2024-0357coderd-repos Eva HTTP POST Request page sql injectioncoderd-repos Eva
CVE-2023-49176WordPress WP Pocket URLs Plugin <= 1.0.2 is vulnerable to Cross Site Scripting (XSS)CodeRevolution WP Pocket URLs
CVE-2018-0562no title heldCoderium Installer of SoundEngine Free

64 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.