CVE-2025-66209
- EPSS 3.93%
- Veröffentlicht 23.12.2025 21:42:18
- Zuletzt bearbeitet 17.03.2026 17:16:13
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/s...
- EPSS 0.45%
- Veröffentlicht 27.08.2025 16:48:03
- Zuletzt bearbeitet 14.07.2026 23:17:20
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embed...
CVE-2025-34159
- EPSS 0.93%
- Veröffentlicht 27.08.2025 16:47:54
- Zuletzt bearbeitet 14.07.2026 23:17:20
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose ...
CVE-2025-34161
- EPSS 2.94%
- Veröffentlicht 27.08.2025 16:47:45
- Zuletzt bearbeitet 14.07.2026 23:17:21
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via ...
CVE-2025-24025
- EPSS 0.23%
- Veröffentlicht 24.01.2025 17:15:15
- Zuletzt bearbeitet 19.09.2025 15:27:52
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags. If the search does not return any results, the query gets reflected on...
- EPSS 0.62%
- Veröffentlicht 24.01.2025 17:15:15
- Zuletzt bearbeitet 19.09.2025 15:27:33
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in...
CVE-2025-22611
- EPSS 0.49%
- Veröffentlicht 24.01.2025 17:15:15
- Zuletzt bearbeitet 19.09.2025 15:26:56
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalate his or any other team members privileges to any r...
CVE-2025-22610
- EPSS 0.39%
- Veröffentlicht 24.01.2025 17:15:15
- Zuletzt bearbeitet 19.09.2025 15:26:31
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the global coolify instance OAuth configuration. Thi...
- EPSS 0.75%
- Veröffentlicht 24.01.2025 17:15:15
- Zuletzt bearbeitet 19.09.2025 15:21:59
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to h...
CVE-2025-22608
- EPSS 0.36%
- Veröffentlicht 24.01.2025 17:15:14
- Zuletzt bearbeitet 19.09.2025 15:14:44
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to revoke any team invitations on a Coolify instance by only ...