CVE-2023-49489: Kodcloud Kodexplorer

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.

Affected products

Published 2023-12-19. Last modified 2026-06-17.