dotclear records
32 published records for vendor dotclear.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-287 Improper Authentication1
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAll records
32 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2005-3957No exploit | Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.dotclear · dotclear | Critical10.0 | — | 1.6% | Dec 1, 2005 |
38Monitor | CVE-2008-3232No exploit | Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbdotclear · dotclear · CWE-94 | Critical9.3 | — | 4.6% | Jul 18, 2008 |
36Monitor | CVE-2016-7902No exploit | Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permidotclear · dotclear · CWE-434 | High8.8 | — | 3.0% | Jan 4, 2017 |
36Monitor | CVE-2015-8832No exploit | Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "dotclear · dotclear · CWE-284 | High8.8 | — | 2.6% | Feb 9, 2017 |
34Monitor | CVE-2023-53952No exploit | Dotclear 2.25.3 Authenticated Remote Code Execution via File Uploaddotclear · dotclear · CWE-434 | High8.7 | — | 1.1% | Dec 19, 2025 |
34Monitor | CVE-2024-58281No exploit | Dotclear 2.29 Remote Code Execution via Authenticated File Uploaddotclear · dotclear · CWE-434 | High8.7 | — | 0.9% | Dec 10, 2025 |
31Monitor | CVE-2011-5083No exploit | Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary coddotclear · dotclear · CWE-264 | High7.5 | — | 3.3% | Mar 19, 2012 |
31Monitor | CVE-2014-1613No exploit | Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-prdotclear · dotclear · CWE-94 | High7.5 | — | 2.3% | May 16, 2014 |
30Monitor | CVE-2016-9268No exploit | Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows dotclear · dotclear · CWE-434 | High7.2 | — | 5.0% | Nov 10, 2016 |
30Monitor | CVE-2005-3963Proof of concept | SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd dotclear · dotclear | High7.5 | — | 1.4% | Dec 1, 2005 |
27Monitor | CVE-2011-1584No exploit | The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, wdotclear · dotclear · CWE-264 | Medium6.5 | — | 1.7% | Jun 8, 2011 |
25Monitor | CVE-2015-8831No exploit | Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web scridotclear · dotclear · CWE-79 | Medium6.1 | — | 2.1% | Feb 9, 2017 |
24Monitor | CVE-2014-3781No exploit | The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via andotclear · dotclear · CWE-287 | Medium5.8 | — | 2.2% | Jun 11, 2014 |
24Monitor | CVE-2014-3783No exploit | SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories pedotclear · dotclear · CWE-89 | Medium6.0 | — | 1.7% | May 22, 2014 |
24Monitor | CVE-2016-6523No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary dotclear · dotclear · CWE-79 | Medium6.1 | — | 1.3% | Dec 9, 2016 |
24Monitor | CVE-2014-3782No exploit | Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow rdotclear · dotclear | Medium6.0 | — | 1.2% | Jun 11, 2014 |
24Monitor | CVE-2017-6446No exploit | XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.dotclear · dotclear · CWE-79 | Medium6.1 | — | 0.7% | Mar 5, 2017 |
24Monitor | CVE-2024-27626No exploit | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29.dotclear · dotclear · CWE-79 | Medium6.1 | — | 0.4% | Mar 20, 2024 |
21Monitor | CVE-2006-2866Proof of concept | PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHPdotclear · dotclear | Medium5.1 | — | 3.2% | Jun 6, 2006 |
21Monitor | CVE-2006-3938No exploit | DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.phpdotclear · dotclear | Medium5.0 | — | 2.3% | Jul 31, 2006 |
21Monitor | CVE-2016-9891No exploit | Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated usedotclear · dotclear · CWE-79 | Medium5.4 | — | 1.0% | Dec 29, 2016 |
21Monitor | CVE-2018-5689No exploit | Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scridotclear · dotclear · CWE-79 | Medium5.4 | — | 0.9% | Jan 14, 2018 |
21Monitor | CVE-2018-5690No exploit | Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scrdotclear · dotclear · CWE-79 | Medium5.4 | — | 0.9% | Jan 14, 2018 |
21Monitor | CVE-2018-16358No exploit | A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authedotclear · dotclear · CWE-79 | Medium5.4 | — | 0.7% | Sep 2, 2018 |
18Monitor | CVE-2012-1039Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML vdotclear · dotclear · CWE-79 | Medium4.3 | — | 4.0% | Mar 19, 2012 |
- CVE-2005-395740Plan
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%dotclear · dotclearDec 1, 2005
- CVE-2008-323238Monitor
Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arb
CriticalCVSS 9.3No exploitEPSS 5%dotclear · dotclearJul 18, 2008
- CVE-2016-790236Monitor
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permi
HighCVSS 8.8No exploitEPSS 3%dotclear · dotclearJan 4, 2017
- CVE-2015-883236Monitor
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "
HighCVSS 8.8No exploitEPSS 3%dotclear · dotclearFeb 9, 2017
- CVE-2023-5395234Monitor
Dotclear 2.25.3 Authenticated Remote Code Execution via File Upload
HighCVSS 8.7No exploitEPSS 1%dotclear · dotclearDec 19, 2025
- CVE-2024-5828134Monitor
Dotclear 2.29 Remote Code Execution via Authenticated File Upload
HighCVSS 8.7No exploitEPSS 1%dotclear · dotclearDec 10, 2025
- CVE-2011-508331Monitor
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary cod
HighCVSS 7.5No exploitEPSS 3%dotclear · dotclearMar 19, 2012
- CVE-2014-161331Monitor
Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-pr
HighCVSS 7.5No exploitEPSS 2%dotclear · dotclearMay 16, 2014
- CVE-2016-926830Monitor
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows
HighCVSS 7.2No exploitEPSS 5%dotclear · dotclearNov 10, 2016
- CVE-2005-396330Monitor
SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd
HighCVSS 7.5Proof of conceptEPSS 1%dotclear · dotclearDec 1, 2005
- CVE-2011-158427Monitor
The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, w
MediumCVSS 6.5No exploitEPSS 2%dotclear · dotclearJun 8, 2011
- CVE-2015-883125Monitor
Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web scri
MediumCVSS 6.1No exploitEPSS 2%dotclear · dotclearFeb 9, 2017
- CVE-2014-378124Monitor
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an
MediumCVSS 5.8No exploitEPSS 2%dotclear · dotclearJun 11, 2014
- CVE-2014-378324Monitor
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories pe
MediumCVSS 6.0No exploitEPSS 2%dotclear · dotclearMay 22, 2014
- CVE-2016-652324Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary
MediumCVSS 6.1No exploitEPSS 1%dotclear · dotclearDec 9, 2016
- CVE-2014-378224Monitor
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow r
MediumCVSS 6.0No exploitEPSS 1%dotclear · dotclearJun 11, 2014
- CVE-2017-644624Monitor
XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.
MediumCVSS 6.1No exploitEPSS 1%dotclear · dotclearMar 5, 2017
- CVE-2024-2762624Monitor
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29.
MediumCVSS 6.1No exploitEPSS 0%dotclear · dotclearMar 20, 2024
- CVE-2006-286621Monitor
PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP
MediumCVSS 5.1Proof of conceptEPSS 3%dotclear · dotclearJun 6, 2006
- CVE-2006-393821Monitor
DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php
MediumCVSS 5.0No exploitEPSS 2%dotclear · dotclearJul 31, 2006
- CVE-2016-989121Monitor
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated use
MediumCVSS 5.4No exploitEPSS 1%dotclear · dotclearDec 29, 2016
- CVE-2018-568921Monitor
Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scri
MediumCVSS 5.4No exploitEPSS 1%dotclear · dotclearJan 14, 2018
- CVE-2018-569021Monitor
Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scr
MediumCVSS 5.4No exploitEPSS 1%dotclear · dotclearJan 14, 2018
- CVE-2018-1635821Monitor
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authe
MediumCVSS 5.4No exploitEPSS 1%dotclear · dotclearSep 2, 2018
- CVE-2012-103918Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML v
MediumCVSS 4.3Proof of conceptEPSS 4%dotclear · dotclearMar 19, 2012