← Vulnerability feed

Vulnerability record · CVE-2019-19208 · published 16 March 2020

CVE-2019-19208: Codiad code injection vulnerability

CCodiad · Codiad

Codiad Web IDE through 2.8.4 allows PHP Code injection.

9.8 CVSS 3.1 Critical EPSS 19% · top 2.8% CWE-94 · Code injection
9.8CVSS 3.1 base score, v2 7.5
19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Codiad Web IDE through 2.8.4 allows PHP Code injection.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19208 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-14009Codiad improper input validation vulnerabilityCodiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.EPSS 38%9.8CVE-2017-11366Codiad os command injection vulnerabilitycomponents/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded …EPSS 7.5%8.8CVE-2020-14043Codiad cross-site request forgery vulnerability** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to down…EPSS 1.5%7.5CVE-2017-20178Codiad information exposure vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function s…EPSS 0.68%7.5CVE-2020-23355Codiad vulnerability** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypa…EPSS 0.99%7.5CVE-2017-1000125Codiad incorrect permission assignment vulnerabilityCodiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.EPSS 0.92%7.2CVE-2020-14044Codiad server-side request forgery (ssrf) vulnerability** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin …EPSS 3.2%7.2CVE-2018-19423Codiad unrestricted file upload vulnerabilityCodiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2019-19208), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.