Skip to main content

Vendor/product archive

coollabs / coolify CVEs

Beta · best-effort

28 CVEs tagged to coollabs / coolify17 Critical, 5 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2025-64425

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initia…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64424

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vu…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-64423

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64422

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertise…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64421

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64420

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged user…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-64419

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59955

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information d…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59158

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a s…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59157

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project crea…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59156

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66213

Published Dec 23, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabili…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66212

Published Dec 23, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabili…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66211

Published Dec 23, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabili…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66210

Published Dec 23, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabili…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66209

Published Dec 23, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabili…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-34161

Published Aug 27, 2025

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, wi…

CVSS 9.4 · Critical
evidence mentions
3
Buzz score
28.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-34159

Published Aug 27, 2025

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users…

CVSS 9.4 · Critical
evidence mentions
3
Buzz score
28.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-34157

Published Aug 27, 2025

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privilege…

CVSS 9.4 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-24025

Published Jan 24, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags.…

CVSS 1.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22612

Published Jan 24, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authentica…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22611

Published Jan 24, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authentic…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22610

Published Jan 24, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authentic…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22609

Published Jan 24, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authentic…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22608

Published Jan 24, 2025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authentic…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2