Where
-Infinity
0

Vendor Risk Score

See how coollabs compares to other vendors in security performance

View Risk Score →

Coollabs CoolifyCoolify has host header injection in forgot password

Risk 64
Severity
8.5
First published (updated )

Coollabs CoolifyColify has command injection vulnerability in project git source

Risk 81
Severity
9.4
First published (updated )

Coollabs CoolifyCoolify has a Privilege Escalation - low privileged users can see and use admin invitation links

Risk 79
Severity
8.8
First published (updated )

Coollabs CoolifyRate-limit bypass on login via X-Forwarded-Host header

Risk 28
Severity
5.5
First published (updated )

Coollabs CoolifyCoolify has a privilege escalation - low privileged user can invite themselves as an admin user

Risk 79
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Coollabs CoolifyCoolify members can see private key of root user

Risk 83
Severity
10
First published (updated )

Coollabs CoolifyCoolify vulnerable to command injection via docker-compose.yaml parameters

Risk 80
Severity
9.7
First published (updated )

other/coolifyCoolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint

Risk 36
Severity
5.7
First published (updated )

Coollabs CoolifyCoolify has Stored XSS in Project Name

Risk 77
Severity
9.4
First published (updated )

Coollabs CoolifyCoolify has Git Repository RCE

Risk 83
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Coollabs CoolifyCoolify has Docker Compose Injection issue

Risk 81
Severity
9.4
First published (updated )

Coollabs CoolifyCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in File Storage Directory Mount Path

Risk 81
Severity
9.4
First published (updated )

Coollabs CoolifyCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Dynamic Proxy Configuration Filename

Risk 81
Severity
9.4
First published (updated )

Coollabs CoolifyCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init Script Filename

Risk 81
Severity
9.4
First published (updated )

Coollabs CoolifyCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Import

Risk 81
Severity
9.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Coollabs CoolifyCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup

Risk 83
Severity
10
First published (updated )

Coollabs CoolifyCoolify Stored Cross-Site Scripting (XSS) in Project Name Field

Risk 77
Severity
9.4
First published (updated )

Coollabs CoolifyCoolify Docker Compose Directive Injection in Application Deployment Workflow

Risk 81
Severity
9.4
First published (updated )

Coollabs CoolifyCoolify Git Repository Field Command Injection in Project Deployment Workflow

Risk 81
Severity
9.4
First published (updated )

Coollabs CoolifyCoolify Vulnerable to Reflected XSS on Tag Search

Risk 27
Severity
6.1
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Coollabs CoolifyCoolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE)

Risk 61
Severity
10
EPSS
0.04%
First published (updated )

Coollabs CoolifyCoolify vulnerable to Privilege Escalation resulting in Remote Command Execution (RCE)

Risk 59
Severity
10
EPSS
0.04%
First published (updated )

Coollabs CoolifyCoolify Vulnerable to OAuth Secrets Leak

Risk 27
Severity
6.5
EPSS
0.04%
First published (updated )

Coollabs CoolifyCoolify Vulnerable to Private Key Hijacking / Remote Command Execution (RCE)

Risk 61
Severity
10
EPSS
0.04%
First published (updated )

Coollabs CoolifyCoolify Vulnerable to Revocation of Arbitrary Team Invitations (DOS)

Risk 28
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Coollabs CoolifyCoolify Vulnerable to GitHub / GitLab OAuth Secrets Leak

Risk 24
Severity
5.5
EPSS
0.04%
First published (updated )

Coolify CoolifyCoolify Command Injection Vulnerability in Project Name

Risk 54
Severity
8.5
EPSS
0.04%
First published (updated )

Coollabs CoolifyCoolify OS Command Injection Vulnerability in SSH Command Generation

Risk 54
Severity
8.5
EPSS
0.05%
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203