Skip to content
Noroxi

html-js records

10 published records for vendor html-js.

All records

10 records
  • DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.

    CriticalCVSS 9.8No exploitEPSS 1%

    html-js · doracmsAug 17, 2022

  • DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords.

    CriticalCVSS 9.8No exploitEPSS 1%

    html-js · doracmsDec 8, 2023

  • DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.

    CriticalCVSS 9.8No exploitEPSS 1%

    html-js · doracmsJan 29, 2024

  • Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 functio

    HighCVSS 8.8Proof of conceptEPSS 1%

    html-js · doracmsMar 19, 2024

  • Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt o

    HighCVSS 7.5No exploitEPSS 0%

    html-js · doracmsMay 20, 2021

  • CVE-2026-3794
    22Monitor

    doramart DoraCMS Email API send improper authentication

    MediumCVSS 5.5No exploitEPSS 1%

    html-js · doracmsMar 8, 2026

  • Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web

    MediumCVSS 5.4No exploitEPSS 1%

    html-js · doracmsSep 6, 2018

  • An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image fil

    MediumCVSS 5.4No exploitEPSS 1%

    html-js · doracmsDec 8, 2023

  • A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrar

    MediumCVSS 4.8No exploitEPSS 0%

    html-js · doracmsMar 20, 2022

  • doramart DoraCMS v1.js createFileBypath path traversal

    LowCVSS 2.1No exploitEPSS 1%

    html-js · doracmsMar 8, 2026