ddsn records
12 published records for vendor ddsn.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-284 Improper Access Control1
- CWE-20 Improper Input Validation1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2025-63314Proof of concept | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset theddsn · cm3 acora cms · CWE-640 | Critical10.0 | — | 0.3% | Jan 12, 2026 |
35Monitor | CVE-2025-25967Proof of concept | Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF).ddsn · acora cms · CWE-352 | High8.8 | — | 0.6% | Mar 3, 2025 |
32Monitor | CVE-2025-22964Proof of concept | DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient inpddsn · cm3 acora content management system · CWE-89 | High8.1 | — | 0.9% | Jan 15, 2025 |
30Monitor | CVE-2006-0221No exploit | SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remddsn · cm3cms | High7.5 | — | 1.2% | Jan 16, 2006 |
27Monitor | CVE-2013-4726No exploit | Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly oddsn · cm3 acora content management system · CWE-352 | Medium6.8 | — | 1.1% | Apr 25, 2014 |
24Monitor | CVE-2013-4723No exploit | Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allowsddsn · cm3 acora content management system · CWE-20 | Medium5.8 | — | 2.0% | Apr 25, 2014 |
24Monitor | CVE-2025-25968Proof of concept | DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability.ddsn · cm3 acora content management system · CWE-284 | Medium6.0 | — | 1.0% | Feb 20, 2025 |
21Monitor | CVE-2013-4727Proof of concept | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain seddsn · cm3 acora content management system · CWE-200 | Medium5.0 | — | 2.7% | Jun 6, 2014 |
20Monitor | CVE-2013-4725No exploit | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an ddsn · cm3 acora content management system · CWE-200 | Medium5.0 | — | 1.2% | Jun 6, 2014 |
20Monitor | CVE-2013-4728No exploit | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain seddsn · cm3 acora content management system · CWE-200 | Medium5.0 | — | 1.2% | Jun 6, 2014 |
20Monitor | CVE-2013-4724No exploit | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag iddsn · cm3 acora content management system · CWE-200 | Medium5.0 | — | 1.2% | Jun 6, 2014 |
18Monitor | CVE-2013-4722No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/1ddsn · cm3 acora content management system · CWE-79 | Medium4.3 | — | 1.9% | Apr 25, 2014 |
- CVE-2025-6331440Plan
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the
CriticalCVSS 10.0Proof of conceptEPSS 0%ddsn · cm3 acora cmsJan 12, 2026
- CVE-2025-2596735Monitor
Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF).
HighCVSS 8.8Proof of conceptEPSS 1%ddsn · acora cmsMar 3, 2025
- CVE-2025-2296432Monitor
DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient inp
HighCVSS 8.1Proof of conceptEPSS 1%ddsn · cm3 acora content management systemJan 15, 2025
- CVE-2006-022130Monitor
SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows rem
HighCVSS 7.5No exploitEPSS 1%ddsn · cm3cmsJan 16, 2006
- CVE-2013-472627Monitor
Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly o
MediumCVSS 6.8No exploitEPSS 1%ddsn · cm3 acora content management systemApr 25, 2014
- CVE-2013-472324Monitor
Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows
MediumCVSS 5.8No exploitEPSS 2%ddsn · cm3 acora content management systemApr 25, 2014
- CVE-2025-2596824Monitor
DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability.
MediumCVSS 6.0Proof of conceptEPSS 1%ddsn · cm3 acora content management systemFeb 20, 2025
- CVE-2013-472721Monitor
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain se
MediumCVSS 5.0Proof of conceptEPSS 3%ddsn · cm3 acora content management systemJun 6, 2014
- CVE-2013-472520Monitor
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an
MediumCVSS 5.0No exploitEPSS 1%ddsn · cm3 acora content management systemJun 6, 2014
- CVE-2013-472820Monitor
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain se
MediumCVSS 5.0No exploitEPSS 1%ddsn · cm3 acora content management systemJun 6, 2014
- CVE-2013-472420Monitor
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag i
MediumCVSS 5.0No exploitEPSS 1%ddsn · cm3 acora content management systemJun 6, 2014
- CVE-2013-472218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/1
MediumCVSS 4.3No exploitEPSS 2%ddsn · cm3 acora content management systemApr 25, 2014