Magicbug

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-44065

    Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.

    Last Modified: Dec 31, 2025
    Published: Dec 26, 2025

    CVE-2025-64084

    An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. This allows a remote, authenticated attacker to execute arbitrary SQL commands by injecting a malicious payload, which is then concatenated directly into a raw SQL query in the vucc_qso_details function.

    Last Modified: Nov 19, 2025
    Published: Nov 14, 2025

    CVE-2024-48259

    Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.

    Last Modified: May 02, 2025
    Published: Oct 14, 2024

    CVE-2024-48253

    Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.

    Last Modified: Oct 16, 2024
    Published: Oct 14, 2024

    CVE-2024-48255

    Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.

    Last Modified: Oct 16, 2024
    Published: Oct 14, 2024
    Items Per Page
    Magicbug Vulnerabilities & Security CVEs | CVE-DB