Skip to content
Noroxi

dotclear records

32 published records for vendor dotclear.

All records

32 records
  • Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.

    CriticalCVSS 10.0No exploitEPSS 2%

    dotclear · dotclearDec 1, 2005

  • CVE-2008-3232
    38Monitor

    Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arb

    CriticalCVSS 9.3No exploitEPSS 5%

    dotclear · dotclearJul 18, 2008

  • CVE-2016-7902
    36Monitor

    Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permi

    HighCVSS 8.8No exploitEPSS 3%

    dotclear · dotclearJan 4, 2017

  • CVE-2015-8832
    36Monitor

    Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "

    HighCVSS 8.8No exploitEPSS 3%

    dotclear · dotclearFeb 9, 2017

  • Dotclear 2.25.3 Authenticated Remote Code Execution via File Upload

    HighCVSS 8.7No exploitEPSS 1%

    dotclear · dotclearDec 19, 2025

  • Dotclear 2.29 Remote Code Execution via Authenticated File Upload

    HighCVSS 8.7No exploitEPSS 1%

    dotclear · dotclearDec 10, 2025

  • CVE-2011-5083
    31Monitor

    Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary cod

    HighCVSS 7.5No exploitEPSS 3%

    dotclear · dotclearMar 19, 2012

  • CVE-2014-1613
    31Monitor

    Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-pr

    HighCVSS 7.5No exploitEPSS 2%

    dotclear · dotclearMay 16, 2014

  • CVE-2016-9268
    30Monitor

    Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows

    HighCVSS 7.2No exploitEPSS 5%

    dotclear · dotclearNov 10, 2016

  • CVE-2005-3963
    30Monitor

    SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd

    HighCVSS 7.5Proof of conceptEPSS 1%

    dotclear · dotclearDec 1, 2005

  • CVE-2011-1584
    27Monitor

    The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, w

    MediumCVSS 6.5No exploitEPSS 2%

    dotclear · dotclearJun 8, 2011

  • CVE-2015-8831
    25Monitor

    Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web scri

    MediumCVSS 6.1No exploitEPSS 2%

    dotclear · dotclearFeb 9, 2017

  • CVE-2014-3781
    24Monitor

    The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an

    MediumCVSS 5.8No exploitEPSS 2%

    dotclear · dotclearJun 11, 2014

  • CVE-2014-3783
    24Monitor

    SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories pe

    MediumCVSS 6.0No exploitEPSS 2%

    dotclear · dotclearMay 22, 2014

  • CVE-2016-6523
    24Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary

    MediumCVSS 6.1No exploitEPSS 1%

    dotclear · dotclearDec 9, 2016

  • CVE-2014-3782
    24Monitor

    Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow r

    MediumCVSS 6.0No exploitEPSS 1%

    dotclear · dotclearJun 11, 2014

  • CVE-2017-6446
    24Monitor

    XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.

    MediumCVSS 6.1No exploitEPSS 1%

    dotclear · dotclearMar 5, 2017

  • A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29.

    MediumCVSS 6.1No exploitEPSS 0%

    dotclear · dotclearMar 20, 2024

  • CVE-2006-2866
    21Monitor

    PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP

    MediumCVSS 5.1Proof of conceptEPSS 3%

    dotclear · dotclearJun 6, 2006

  • CVE-2006-3938
    21Monitor

    DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php

    MediumCVSS 5.0No exploitEPSS 2%

    dotclear · dotclearJul 31, 2006

  • CVE-2016-9891
    21Monitor

    Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated use

    MediumCVSS 5.4No exploitEPSS 1%

    dotclear · dotclearDec 29, 2016

  • CVE-2018-5689
    21Monitor

    Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scri

    MediumCVSS 5.4No exploitEPSS 1%

    dotclear · dotclearJan 14, 2018

  • CVE-2018-5690
    21Monitor

    Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scr

    MediumCVSS 5.4No exploitEPSS 1%

    dotclear · dotclearJan 14, 2018

  • A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authe

    MediumCVSS 5.4No exploitEPSS 1%

    dotclear · dotclearSep 2, 2018

  • CVE-2012-1039
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML v

    MediumCVSS 4.3Proof of conceptEPSS 4%

    dotclear · dotclearMar 19, 2012