Skip to content
Noroxi

dotCMS records

57 published records for vendor dotcms.

All records

57 records
  • An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02.

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    dotcms · dotcmsJul 17, 2022

  • CVE-2020-6754
    67This week

    dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.

    CriticalCVSS 9.8No exploitEPSS 95%

    dotcms · dotcmsFeb 5, 2020

  • An issue was discovered in dotCMS through 3.6.1.

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    dotcms · dotcmsFeb 17, 2017

  • Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the compon

    CriticalCVSS 9.8No exploitEPSS 6%

    dotcms · dotcmsSep 8, 2021

  • SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arb

    CriticalCVSS 9.8No exploitEPSS 3%

    dotcms · dotcmsNov 14, 2016

  • SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName

    CriticalCVSS 9.8No exploitEPSS 2%

    dotcms · dotcmsDec 19, 2016

  • A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileg

    CriticalCVSS 9.4No exploitEPSS 0%

    dotcms · dotcmsFeb 24, 2026

  • CVE-2016-8906
    36Monitor

    SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execu

    HighCVSS 8.8No exploitEPSS 2%

    dotcms · dotcmsNov 14, 2016

  • CVE-2016-8907
    36Monitor

    SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to ex

    HighCVSS 8.8No exploitEPSS 2%

    dotcms · dotcmsNov 14, 2016

  • CVE-2016-8908
    36Monitor

    SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execut

    HighCVSS 8.8No exploitEPSS 2%

    dotcms · dotcmsNov 14, 2016

  • CVE-2016-8905
    36Monitor

    SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL co

    HighCVSS 8.8No exploitEPSS 2%

    dotcms · dotcmsNov 14, 2016

  • Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl

    HighCVSS 8.8No exploitEPSS 2%

    dotcms · dotcmsAug 18, 2021

  • CVE-2016-8903
    36Monitor

    SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to e

    HighCVSS 8.8No exploitEPSS 2%

    dotcms · dotcmsNov 14, 2016

  • CVE-2016-8904
    36Monitor

    SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to

    HighCVSS 8.8No exploitEPSS 2%

    dotcms · dotcmsNov 14, 2016

  • dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter.

    HighCVSS 8.8No exploitEPSS 1%

    dotcms · dotcmsDec 30, 2020

  • CVE-2017-3187
    35Monitor

    The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery

    HighCVSS 8.8No exploitEPSS 1%

    dotcms · dotcmsJul 24, 2018

  • An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1.

    HighCVSS 8.8Proof of conceptEPSS 1%

    dotcms · dotcmsFeb 1, 2023

  • CVE-2017-3189
    34Monitor

    The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload

    HighCVSS 8.1No exploitEPSS 6%

    dotcms · dotcmsJul 24, 2018

  • CVE-2016-4803
    31Monitor

    CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email header

    HighCVSS 7.5No exploitEPSS 2%

    dotcms · dotcmsJun 30, 2016

  • CVE-2016-8600
    31Monitor

    In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check l

    HighCVSS 7.5No exploitEPSS 2%

    dotcms · dotcmsOct 28, 2016

  • Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated adm

    HighCVSS 7.2No exploitEPSS 8%

    dotcms · dotcmsJul 19, 2017

  • An issue was discovered in dotCMS core 4.x through 22.10.2.

    MediumCVSS 6.5No exploitEPSS 8%

    dotcms · dotcmsFeb 1, 2023

  • CVE-2016-4040
    28Monitor

    SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via

    HighCVSS 7.2No exploitEPSS 1%

    dotcms · dotcmsApr 19, 2016

  • dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.js

    HighCVSS 7.2No exploitEPSS 1%

    dotcms · dotcmsJun 18, 2019

  • SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenti

    HighCVSS 7.2No exploitEPSS 1%

    dotcms · dotcmsFeb 19, 2018