CVE-2025-59156
- EPSS 0.42%
- Veröffentlicht 05.01.2026 17:39:42
- Zuletzt bearbeitet 12.01.2026 15:03:44
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability exists in Coolify's application deployment workflow. This flaw allows a...
CVE-2025-66211
- EPSS 0.41%
- Veröffentlicht 23.12.2025 22:15:52
- Zuletzt bearbeitet 06.01.2026 16:15:52
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in PostgreSQL Init Script Filename handling allows users with applic...
CVE-2025-66213
- EPSS 0.2%
- Veröffentlicht 23.12.2025 22:15:52
- Zuletzt bearbeitet 06.01.2026 16:15:53
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the File Storage Directory Mount Path functionality allows users ...
CVE-2025-66212
- EPSS 0.2%
- Veröffentlicht 23.12.2025 22:15:52
- Zuletzt bearbeitet 06.01.2026 16:15:52
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Dynamic Proxy Configuration Filename handling allows users wi...
CVE-2025-66210
- EPSS 0.41%
- Veröffentlicht 23.12.2025 21:49:44
- Zuletzt bearbeitet 06.01.2026 16:15:52
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Import functionality allows users with application/s...
CVE-2025-66209
- EPSS 0.2%
- Veröffentlicht 23.12.2025 21:42:18
- Zuletzt bearbeitet 07.01.2026 21:22:43
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/s...
- EPSS 0.06%
- Veröffentlicht 27.08.2025 16:48:03
- Zuletzt bearbeitet 19.09.2025 16:48:52
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embed...
CVE-2025-34159
- EPSS 0.48%
- Veröffentlicht 27.08.2025 16:47:54
- Zuletzt bearbeitet 19.09.2025 16:44:12
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose ...
CVE-2025-34161
- EPSS 0.51%
- Veröffentlicht 27.08.2025 16:47:45
- Zuletzt bearbeitet 19.09.2025 16:37:02
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via ...
CVE-2025-24025
- EPSS 0.21%
- Veröffentlicht 24.01.2025 17:15:15
- Zuletzt bearbeitet 19.09.2025 15:27:52
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags. If the search does not return any results, the query gets reflected on...