Перейти к содержимому
Noroxi

Записи dotCMS

57 опубликованных записей вендора dotcms.

Профиль для исследователя

Попали в KEV
1 · 1,8 %
С эксплойтом
1 · 1,8 %
Pre-auth RCE
7
С записью об исправлении
5,3 %
Медиана: публикация → KEV
39 дн.

Все записи

57 записей
  • CVE-2022-26352
    96Срочно

    An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %

    dotcms · dotcms17 июл. 2022 г.

  • CVE-2020-6754
    67На этой неделе

    dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.

    КритическаяCVSS 9,8Эксплойта нетEPSS 95 %

    dotcms · dotcms5 февр. 2020 г.

  • CVE-2017-5344
    41В плане

    An issue was discovered in dotCMS through 3.6.1.

    КритическаяCVSS 9,8Proof of conceptEPSS 6 %

    dotcms · dotcms17 февр. 2017 г.

  • CVE-2020-19138
    41В плане

    Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the compon

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    dotcms · dotcms8 сент. 2021 г.

  • CVE-2016-8902
    40В плане

    SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arb

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    dotcms · dotcms14 нояб. 2016 г.

  • CVE-2016-2355
    40В плане

    SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dotcms · dotcms19 дек. 2016 г.

  • CVE-2025-11165
    37Наблюдать

    A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileg

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    dotcms · dotcms24 февр. 2026 г.

  • CVE-2016-8906
    36Наблюдать

    SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execu

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    dotcms · dotcms14 нояб. 2016 г.

  • CVE-2016-8907
    36Наблюдать

    SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to ex

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    dotcms · dotcms14 нояб. 2016 г.

  • CVE-2016-8908
    36Наблюдать

    SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execut

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    dotcms · dotcms14 нояб. 2016 г.

  • CVE-2016-8905
    36Наблюдать

    SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL co

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    dotcms · dotcms14 нояб. 2016 г.

  • CVE-2020-18875
    36Наблюдать

    Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    dotcms · dotcms18 авг. 2021 г.

  • CVE-2016-8903
    36Наблюдать

    SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to e

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    dotcms · dotcms14 нояб. 2016 г.

  • CVE-2016-8904
    36Наблюдать

    SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    dotcms · dotcms14 нояб. 2016 г.

  • CVE-2020-27848
    35Наблюдать

    dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    dotcms · dotcms30 дек. 2020 г.

  • CVE-2017-3187
    35Наблюдать

    The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    dotcms · dotcms24 июл. 2018 г.

  • CVE-2022-45782
    35Наблюдать

    An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1.

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    dotcms · dotcms1 февр. 2023 г.

  • CVE-2017-3189
    34Наблюдать

    The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload

    ВысокаяCVSS 8,1Эксплойта нетEPSS 6 %

    dotcms · dotcms24 июл. 2018 г.

  • CVE-2016-4803
    31Наблюдать

    CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email header

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    dotcms · dotcms30 июн. 2016 г.

  • CVE-2016-8600
    31Наблюдать

    In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check l

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    dotcms · dotcms28 окт. 2016 г.

  • CVE-2017-11466
    30Наблюдать

    Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated adm

    ВысокаяCVSS 7,2Эксплойта нетEPSS 8 %

    dotcms · dotcms19 июл. 2017 г.

  • CVE-2022-45783
    29Наблюдать

    An issue was discovered in dotCMS core 4.x through 22.10.2.

    СредняяCVSS 6,5Эксплойта нетEPSS 8 %

    dotcms · dotcms1 февр. 2023 г.

  • CVE-2016-4040
    28Наблюдать

    SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    dotcms · dotcms19 апр. 2016 г.

  • CVE-2019-12872
    28Наблюдать

    dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.js

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    dotcms · dotcms18 июн. 2019 г.

  • CVE-2016-10008
    28Наблюдать

    SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenti

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    dotcms · dotcms19 февр. 2018 г.