<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Coder (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/coder.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/coder-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Coder (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-28693 – ImageMagick is free and open-source software used for editing and manipulating d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28693</guid>
    <pubDate>Tue, 10 Mar 2026 07:43:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28693</strong></p>
  <p>ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22600 – OpenProject is an open-source, web-based project management software. A Local Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22600</guid>
    <pubDate>Sat, 10 Jan 2026 02:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22600</strong></p>
  <p>OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior to version 16.6.4. By uploading a specially crafted SVG file (disguised as a PNG) as a work package attachment, an attacker can exploit the backend image processing engine (ImageMagick). When the work package is export…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66411 – Coder allows organizations to provision remote development environments via Terr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66411</guid>
    <pubDate>Wed, 03 Dec 2025 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66411</strong></p>
  <p>Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system (SIEM, logging stack) could access those logs. This vulnerability is fixed in 2…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58437 – Coder allows organizations to provision remote development environments via Terr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58437</guid>
    <pubDate>Sat, 06 Sep 2025 03:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58437</strong></p>
  <p>Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0  and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a user when a workspace is started. It is automatically exposed via coder_workspace_owner.session_token. Prebuilt workspaces…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-277</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13726 – The  Coder  WordPress plugin through 1.3.4 does not properly sanitise and escape...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13726</guid>
    <pubDate>Mon, 17 Feb 2025 06:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13726</strong></p>
  <p>The  Coder  WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24699 – Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company WP Coder wp-coder...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24699</guid>
    <pubDate>Fri, 14 Feb 2025 13:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24699</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company WP Coder wp-coder allows Cross-Site Scripting (XSS).This issue affects WP Coder: from n/a through <= 3.6.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-12402 – The Themes Coder – Create Android &amp; iOS Apps For Your Woocommerce Site plugin fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12402</guid>
    <pubDate>Tue, 07 Jan 2025 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-12402</strong></p>
  <p>The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.4. This is due to the plugin not properly validating a user's identity prior to updating their password through the update_user_profile() function. This makes it possible for unauthenticated attackers to ch…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27918 – Coder allows oragnizations to provision remote development environments via Terr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27918</guid>
    <pubDate>Thu, 21 Mar 2024 02:52:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27918</strong></p>
  <p>Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, and 2.8.4, a vulnerability in Coder's OIDC authentication could allow an attacker to bypass the `CODER_OIDC_EMAIL_DOMAIN` verification and create an account with an email not in the allowlist. Deployments are only affected if the OIDC provider allows users to create accounts on t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0895 – The WP Coder – add custom html, css and js code plugin for WordPress is vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0895</guid>
    <pubDate>Fri, 17 Feb 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0895</strong></p>
  <p>The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers with administrative privileges to append additional…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25053 – The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu pag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25053</guid>
    <pubDate>Mon, 10 Jan 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25053</strong></p>
  <p>The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-17783 – In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coder...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17783</guid>
    <pubDate>Wed, 20 Dec 2017 09:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-17783</strong></p>
  <p>In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12666 – ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteINLINEImage in coder...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12666</guid>
    <pubDate>Mon, 07 Aug 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12666</strong></p>
  <p>ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteINLINEImage in coders/inline.c.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-9849 – The png coder in ImageMagick allows remote attackers to cause a denial of servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9849</guid>
    <pubDate>Mon, 20 Mar 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-9849</strong></p>
  <p>The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6823 – Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6823</guid>
    <pubDate>Wed, 18 Jan 2017 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6823</strong></p>
  <p>Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5687 – The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5687</guid>
    <pubDate>Tue, 13 Dec 2016 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5687</strong></p>
  <p>The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-bounds read.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4469 – SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4469</guid>
    <pubDate>Tue, 07 Oct 2008 00:31:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4469</strong></p>
  <p>SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the coder_id parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4469">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
