dotCMS records
57 published records for vendor dotcms.
Researcher profile
- Entered KEV
- 1 · 1.8%
- Weaponized
- 1 · 1.8%
- Pre-auth RCE
- 7
- With a fix record
- 5.3%
- Median publish → KEV
- 39 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')19
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-284 Improper Access Control1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
57 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
96Now | CVE-2022-26352Weaponized | An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02.dotcms · dotcms | Critical9.8 | KEV | 91.6% | Jul 17, 2022 |
67This week | CVE-2020-6754No exploit | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.dotcms · dotcms · CWE-22 | Critical9.8 | — | 94.8% | Feb 5, 2020 |
41Plan | CVE-2017-5344Proof of concept | An issue was discovered in dotCMS through 3.6.1.dotcms · dotcms · CWE-89 | Critical9.8 | — | 6.3% | Feb 17, 2017 |
41Plan | CVE-2020-19138No exploit | Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the compondotcms · dotcms · CWE-434 | Critical9.8 | — | 5.7% | Sep 8, 2021 |
40Plan | CVE-2016-8902No exploit | SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbdotcms · dotcms · CWE-89 | Critical9.8 | — | 2.8% | Nov 14, 2016 |
40Plan | CVE-2016-2355No exploit | SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName dotcms · dotcms · CWE-89 | Critical9.8 | — | 2.1% | Dec 19, 2016 |
37Monitor | CVE-2025-11165No exploit | A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privilegdotcms · dotcms · CWE-89 | Critical9.4 | — | 0.3% | Feb 24, 2026 |
36Monitor | CVE-2016-8906No exploit | SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execudotcms · dotcms · CWE-89 | High8.8 | — | 2.0% | Nov 14, 2016 |
36Monitor | CVE-2016-8907No exploit | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to exdotcms · dotcms · CWE-89 | High8.8 | — | 2.0% | Nov 14, 2016 |
36Monitor | CVE-2016-8908No exploit | SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to executdotcms · dotcms · CWE-89 | High8.8 | — | 2.0% | Nov 14, 2016 |
36Monitor | CVE-2016-8905No exploit | SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL codotcms · dotcms · CWE-89 | High8.8 | — | 2.0% | Nov 14, 2016 |
36Monitor | CVE-2020-18875No exploit | Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtldotcms · dotcms · CWE-74 | High8.8 | — | 2.0% | Aug 18, 2021 |
36Monitor | CVE-2016-8903No exploit | SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to edotcms · dotcms · CWE-89 | High8.8 | — | 1.9% | Nov 14, 2016 |
36Monitor | CVE-2016-8904No exploit | SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to dotcms · dotcms · CWE-89 | High8.8 | — | 1.9% | Nov 14, 2016 |
35Monitor | CVE-2020-27848No exploit | dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter.dotcms · dotcms · CWE-89 | High8.8 | — | 1.2% | Dec 30, 2020 |
35Monitor | CVE-2017-3187No exploit | The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgerydotcms · dotcms · CWE-352 | High8.8 | — | 1.1% | Jul 24, 2018 |
35Monitor | CVE-2022-45782Proof of concept | An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1.dotcms · dotcms · CWE-338 | High8.8 | — | 0.6% | Feb 1, 2023 |
34Monitor | CVE-2017-3189No exploit | The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file uploaddotcms · dotcms · CWE-434 | High8.1 | — | 6.5% | Jul 24, 2018 |
31Monitor | CVE-2016-4803No exploit | CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headerdotcms · dotcms | High7.5 | — | 2.2% | Jun 30, 2016 |
31Monitor | CVE-2016-8600No exploit | In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check ldotcms · dotcms · CWE-254 | High7.5 | — | 1.8% | Oct 28, 2016 |
30Monitor | CVE-2017-11466No exploit | Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated admdotcms · dotcms · CWE-434 | High7.2 | — | 7.7% | Jul 19, 2017 |
29Monitor | CVE-2022-45783No exploit | An issue was discovered in dotCMS core 4.x through 22.10.2.dotcms · dotcms · CWE-22 | Medium6.5 | — | 8.5% | Feb 1, 2023 |
28Monitor | CVE-2016-4040No exploit | SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands viadotcms · dotcms · CWE-89 | High7.2 | — | 1.3% | Apr 19, 2016 |
28Monitor | CVE-2019-12872No exploit | dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsdotcms · dotcms · CWE-89 | High7.2 | — | 1.3% | Jun 18, 2019 |
28Monitor | CVE-2016-10008No exploit | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authentidotcms · dotcms · CWE-89 | High7.2 | — | 1.3% | Feb 19, 2018 |
- CVE-2022-2635296Now
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02.
CriticalCVSS 9.8KEVWeaponizedEPSS 92%dotcms · dotcmsJul 17, 2022
- CVE-2020-675467This week
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.
CriticalCVSS 9.8No exploitEPSS 95%dotcms · dotcmsFeb 5, 2020
- CVE-2017-534441Plan
An issue was discovered in dotCMS through 3.6.1.
CriticalCVSS 9.8Proof of conceptEPSS 6%dotcms · dotcmsFeb 17, 2017
- CVE-2020-1913841Plan
Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the compon
CriticalCVSS 9.8No exploitEPSS 6%dotcms · dotcmsSep 8, 2021
- CVE-2016-890240Plan
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arb
CriticalCVSS 9.8No exploitEPSS 3%dotcms · dotcmsNov 14, 2016
- CVE-2016-235540Plan
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName
CriticalCVSS 9.8No exploitEPSS 2%dotcms · dotcmsDec 19, 2016
- CVE-2025-1116537Monitor
A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileg
CriticalCVSS 9.4No exploitEPSS 0%dotcms · dotcmsFeb 24, 2026
- CVE-2016-890636Monitor
SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execu
HighCVSS 8.8No exploitEPSS 2%dotcms · dotcmsNov 14, 2016
- CVE-2016-890736Monitor
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to ex
HighCVSS 8.8No exploitEPSS 2%dotcms · dotcmsNov 14, 2016
- CVE-2016-890836Monitor
SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execut
HighCVSS 8.8No exploitEPSS 2%dotcms · dotcmsNov 14, 2016
- CVE-2016-890536Monitor
SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL co
HighCVSS 8.8No exploitEPSS 2%dotcms · dotcmsNov 14, 2016
- CVE-2020-1887536Monitor
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl
HighCVSS 8.8No exploitEPSS 2%dotcms · dotcmsAug 18, 2021
- CVE-2016-890336Monitor
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to e
HighCVSS 8.8No exploitEPSS 2%dotcms · dotcmsNov 14, 2016
- CVE-2016-890436Monitor
SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to
HighCVSS 8.8No exploitEPSS 2%dotcms · dotcmsNov 14, 2016
- CVE-2020-2784835Monitor
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter.
HighCVSS 8.8No exploitEPSS 1%dotcms · dotcmsDec 30, 2020
- CVE-2017-318735Monitor
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery
HighCVSS 8.8No exploitEPSS 1%dotcms · dotcmsJul 24, 2018
- CVE-2022-4578235Monitor
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1.
HighCVSS 8.8Proof of conceptEPSS 1%dotcms · dotcmsFeb 1, 2023
- CVE-2017-318934Monitor
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload
HighCVSS 8.1No exploitEPSS 6%dotcms · dotcmsJul 24, 2018
- CVE-2016-480331Monitor
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email header
HighCVSS 7.5No exploitEPSS 2%dotcms · dotcmsJun 30, 2016
- CVE-2016-860031Monitor
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check l
HighCVSS 7.5No exploitEPSS 2%dotcms · dotcmsOct 28, 2016
- CVE-2017-1146630Monitor
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated adm
HighCVSS 7.2No exploitEPSS 8%dotcms · dotcmsJul 19, 2017
- CVE-2022-4578329Monitor
An issue was discovered in dotCMS core 4.x through 22.10.2.
MediumCVSS 6.5No exploitEPSS 8%dotcms · dotcmsFeb 1, 2023
- CVE-2016-404028Monitor
SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via
HighCVSS 7.2No exploitEPSS 1%dotcms · dotcmsApr 19, 2016
- CVE-2019-1287228Monitor
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.js
HighCVSS 7.2No exploitEPSS 1%dotcms · dotcmsJun 18, 2019
- CVE-2016-1000828Monitor
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenti
HighCVSS 7.2No exploitEPSS 1%dotcms · dotcmsFeb 19, 2018