Записи dotCMS
57 опубликованных записей вендора dotcms.
Профиль для исследователя
- Попали в KEV
- 1 · 1,8 %
- С эксплойтом
- 1 · 1,8 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 5,3 %
- Медиана: публикация → KEV
- 39 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')19
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-284 Improper Access Control1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
57 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
96Срочно | CVE-2022-26352Готовый эксплойт | An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02.dotcms · dotcms | Критическая9,8 | KEV | 91,6 % | 17 июл. 2022 г. |
67На этой неделе | CVE-2020-6754Эксплойта нет | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.dotcms · dotcms · CWE-22 | Критическая9,8 | — | 94,8 % | 5 февр. 2020 г. |
41В плане | CVE-2017-5344Proof of concept | An issue was discovered in dotCMS through 3.6.1.dotcms · dotcms · CWE-89 | Критическая9,8 | — | 6,3 % | 17 февр. 2017 г. |
41В плане | CVE-2020-19138Эксплойта нет | Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the compondotcms · dotcms · CWE-434 | Критическая9,8 | — | 5,7 % | 8 сент. 2021 г. |
40В плане | CVE-2016-8902Эксплойта нет | SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbdotcms · dotcms · CWE-89 | Критическая9,8 | — | 2,8 % | 14 нояб. 2016 г. |
40В плане | CVE-2016-2355Эксплойта нет | SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName dotcms · dotcms · CWE-89 | Критическая9,8 | — | 2,1 % | 19 дек. 2016 г. |
37Наблюдать | CVE-2025-11165Эксплойта нет | A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privilegdotcms · dotcms · CWE-89 | Критическая9,4 | — | 0,3 % | 24 февр. 2026 г. |
36Наблюдать | CVE-2016-8906Эксплойта нет | SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execudotcms · dotcms · CWE-89 | Высокая8,8 | — | 2,0 % | 14 нояб. 2016 г. |
36Наблюдать | CVE-2016-8907Эксплойта нет | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to exdotcms · dotcms · CWE-89 | Высокая8,8 | — | 2,0 % | 14 нояб. 2016 г. |
36Наблюдать | CVE-2016-8908Эксплойта нет | SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to executdotcms · dotcms · CWE-89 | Высокая8,8 | — | 2,0 % | 14 нояб. 2016 г. |
36Наблюдать | CVE-2016-8905Эксплойта нет | SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL codotcms · dotcms · CWE-89 | Высокая8,8 | — | 2,0 % | 14 нояб. 2016 г. |
36Наблюдать | CVE-2020-18875Эксплойта нет | Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtldotcms · dotcms · CWE-74 | Высокая8,8 | — | 2,0 % | 18 авг. 2021 г. |
36Наблюдать | CVE-2016-8903Эксплойта нет | SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to edotcms · dotcms · CWE-89 | Высокая8,8 | — | 1,9 % | 14 нояб. 2016 г. |
36Наблюдать | CVE-2016-8904Эксплойта нет | SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to dotcms · dotcms · CWE-89 | Высокая8,8 | — | 1,9 % | 14 нояб. 2016 г. |
35Наблюдать | CVE-2020-27848Эксплойта нет | dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter.dotcms · dotcms · CWE-89 | Высокая8,8 | — | 1,2 % | 30 дек. 2020 г. |
35Наблюдать | CVE-2017-3187Эксплойта нет | The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgerydotcms · dotcms · CWE-352 | Высокая8,8 | — | 1,1 % | 24 июл. 2018 г. |
35Наблюдать | CVE-2022-45782Proof of concept | An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1.dotcms · dotcms · CWE-338 | Высокая8,8 | — | 0,6 % | 1 февр. 2023 г. |
34Наблюдать | CVE-2017-3189Эксплойта нет | The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file uploaddotcms · dotcms · CWE-434 | Высокая8,1 | — | 6,5 % | 24 июл. 2018 г. |
31Наблюдать | CVE-2016-4803Эксплойта нет | CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headerdotcms · dotcms | Высокая7,5 | — | 2,2 % | 30 июн. 2016 г. |
31Наблюдать | CVE-2016-8600Эксплойта нет | In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check ldotcms · dotcms · CWE-254 | Высокая7,5 | — | 1,8 % | 28 окт. 2016 г. |
30Наблюдать | CVE-2017-11466Эксплойта нет | Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated admdotcms · dotcms · CWE-434 | Высокая7,2 | — | 7,7 % | 19 июл. 2017 г. |
29Наблюдать | CVE-2022-45783Эксплойта нет | An issue was discovered in dotCMS core 4.x through 22.10.2.dotcms · dotcms · CWE-22 | Средняя6,5 | — | 8,5 % | 1 февр. 2023 г. |
28Наблюдать | CVE-2016-4040Эксплойта нет | SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands viadotcms · dotcms · CWE-89 | Высокая7,2 | — | 1,3 % | 19 апр. 2016 г. |
28Наблюдать | CVE-2019-12872Эксплойта нет | dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsdotcms · dotcms · CWE-89 | Высокая7,2 | — | 1,3 % | 18 июн. 2019 г. |
28Наблюдать | CVE-2016-10008Эксплойта нет | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authentidotcms · dotcms · CWE-89 | Высокая7,2 | — | 1,3 % | 19 февр. 2018 г. |
- CVE-2022-2635296Срочно
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %dotcms · dotcms17 июл. 2022 г.
- CVE-2020-675467На этой неделе
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.
КритическаяCVSS 9,8Эксплойта нетEPSS 95 %dotcms · dotcms5 февр. 2020 г.
- CVE-2017-534441В плане
An issue was discovered in dotCMS through 3.6.1.
КритическаяCVSS 9,8Proof of conceptEPSS 6 %dotcms · dotcms17 февр. 2017 г.
- CVE-2020-1913841В плане
Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the compon
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %dotcms · dotcms8 сент. 2021 г.
- CVE-2016-890240В плане
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arb
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %dotcms · dotcms14 нояб. 2016 г.
- CVE-2016-235540В плане
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dotcms · dotcms19 дек. 2016 г.
- CVE-2025-1116537Наблюдать
A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileg
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %dotcms · dotcms24 февр. 2026 г.
- CVE-2016-890636Наблюдать
SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execu
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dotcms · dotcms14 нояб. 2016 г.
- CVE-2016-890736Наблюдать
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to ex
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dotcms · dotcms14 нояб. 2016 г.
- CVE-2016-890836Наблюдать
SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execut
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dotcms · dotcms14 нояб. 2016 г.
- CVE-2016-890536Наблюдать
SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL co
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dotcms · dotcms14 нояб. 2016 г.
- CVE-2020-1887536Наблюдать
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dotcms · dotcms18 авг. 2021 г.
- CVE-2016-890336Наблюдать
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to e
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dotcms · dotcms14 нояб. 2016 г.
- CVE-2016-890436Наблюдать
SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dotcms · dotcms14 нояб. 2016 г.
- CVE-2020-2784835Наблюдать
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dotcms · dotcms30 дек. 2020 г.
- CVE-2017-318735Наблюдать
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dotcms · dotcms24 июл. 2018 г.
- CVE-2022-4578235Наблюдать
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1.
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %dotcms · dotcms1 февр. 2023 г.
- CVE-2017-318934Наблюдать
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload
ВысокаяCVSS 8,1Эксплойта нетEPSS 6 %dotcms · dotcms24 июл. 2018 г.
- CVE-2016-480331Наблюдать
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email header
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dotcms · dotcms30 июн. 2016 г.
- CVE-2016-860031Наблюдать
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check l
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dotcms · dotcms28 окт. 2016 г.
- CVE-2017-1146630Наблюдать
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated adm
ВысокаяCVSS 7,2Эксплойта нетEPSS 8 %dotcms · dotcms19 июл. 2017 г.
- CVE-2022-4578329Наблюдать
An issue was discovered in dotCMS core 4.x through 22.10.2.
СредняяCVSS 6,5Эксплойта нетEPSS 8 %dotcms · dotcms1 февр. 2023 г.
- CVE-2016-404028Наблюдать
SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %dotcms · dotcms19 апр. 2016 г.
- CVE-2019-1287228Наблюдать
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.js
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %dotcms · dotcms18 июн. 2019 г.
- CVE-2016-1000828Наблюдать
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenti
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %dotcms · dotcms19 февр. 2018 г.