CVE-2017-11366: Codiad

Critical severity, CVSS 9.8. EPSS: 7.5% chance of exploitation in the next 30 days.

components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type.

Affected products

  • Codiad Codiad: up to and including 2.8.3

Published 2017-08-21. Last modified 2026-06-17.