Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| coollabsio | coolify | <= 4.0.0-beta.428 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-64420 | 10.0 CRITICAL | Coolify members can see private key of root user |
| CVE-2025-59157 | 10.0 CRITICAL | Coolify has Git Repository RCE |
| CVE-2025-64419 | 9.7 CRITICAL | Coolify vulnerable to command injection via docker-compose.yaml parameters |
| CVE-2025-64424 | Colify has command injection vulnerability in project git source | |
| CVE-2025-64421 | Coolify has a privilege escalation - low privileged user can invite themselves as an admin | |
| CVE-2025-64423 | Coolify has a Privilege Escalation - low privileged users can see and use admin invitation | |
| CVE-2025-64422 | Rate-limit bypass on login via X-Forwarded-Host header | |
| CVE-2025-64425 | Coolify has host header injection in forgot password | |
| CVE-2025-59158 | Coolify has Stored XSS in Project Name | |
| CVE-2025-59156 | Coolify has Docker Compose Injection issue |
No comments yet