html-js records
10 published records for vendor html-js.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-326 Inadequate Encryption Strength1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-35147No exploit | DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.html-js · doracms · CWE-200 | Critical9.8 | — | 1.5% | Aug 17, 2022 |
39Monitor | CVE-2023-49443No exploit | DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords.html-js · doracms · CWE-307 | Critical9.8 | — | 0.8% | Dec 8, 2023 |
39Monitor | CVE-2023-51840No exploit | DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.html-js · doracms · CWE-798 | Critical9.8 | — | 0.6% | Jan 29, 2024 |
35Monitor | CVE-2024-28715Proof of concept | Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 functiohtml-js · doracms · CWE-79 | High8.8 | — | 1.1% | Mar 19, 2024 |
30Monitor | CVE-2020-18220No exploit | Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt ohtml-js · doracms · CWE-326 | High7.5 | — | 0.4% | May 20, 2021 |
22Monitor | CVE-2026-3794No exploit | doramart DoraCMS Email API send improper authenticationhtml-js · doracms · CWE-287 | Medium5.5 | — | 1.0% | Mar 8, 2026 |
21Monitor | CVE-2018-16622No exploit | Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web html-js · doracms · CWE-79 | Medium5.4 | — | 0.8% | Sep 6, 2018 |
21Monitor | CVE-2023-49444No exploit | An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image filhtml-js · doracms · CWE-79 | Medium5.4 | — | 0.5% | Dec 8, 2023 |
19Monitor | CVE-2022-25464No exploit | A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrarhtml-js · doracms · CWE-79 | Medium4.8 | — | 0.4% | Mar 20, 2022 |
8Monitor | CVE-2026-3795No exploit | doramart DoraCMS v1.js createFileBypath path traversalhtml-js · doracms · CWE-22 | Low2.1 | — | 0.8% | Mar 8, 2026 |
- CVE-2022-3514739Monitor
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
CriticalCVSS 9.8No exploitEPSS 1%html-js · doracmsAug 17, 2022
- CVE-2023-4944339Monitor
DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords.
CriticalCVSS 9.8No exploitEPSS 1%html-js · doracmsDec 8, 2023
- CVE-2023-5184039Monitor
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
CriticalCVSS 9.8No exploitEPSS 1%html-js · doracmsJan 29, 2024
- CVE-2024-2871535Monitor
Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 functio
HighCVSS 8.8Proof of conceptEPSS 1%html-js · doracmsMar 19, 2024
- CVE-2020-1822030Monitor
Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt o
HighCVSS 7.5No exploitEPSS 0%html-js · doracmsMay 20, 2021
- CVE-2026-379422Monitor
doramart DoraCMS Email API send improper authentication
MediumCVSS 5.5No exploitEPSS 1%html-js · doracmsMar 8, 2026
- CVE-2018-1662221Monitor
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web
MediumCVSS 5.4No exploitEPSS 1%html-js · doracmsSep 6, 2018
- CVE-2023-4944421Monitor
An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image fil
MediumCVSS 5.4No exploitEPSS 1%html-js · doracmsDec 8, 2023
- CVE-2022-2546419Monitor
A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrar
MediumCVSS 4.8No exploitEPSS 0%html-js · doracmsMar 20, 2022
- CVE-2026-37958Monitor
doramart DoraCMS v1.js createFileBypath path traversal
LowCVSS 2.1No exploitEPSS 1%html-js · doracmsMar 8, 2026