Записи html-js
10 опубликованных записей вендора html-js.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-326 Inadequate Encryption Strength1
- CWE-798 Use of Hard-coded Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-35147Эксплойта нет | DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.html-js · doracms · CWE-200 | Критическая9,8 | — | 1,5 % | 17 авг. 2022 г. |
39Наблюдать | CVE-2023-49443Эксплойта нет | DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords.html-js · doracms · CWE-307 | Критическая9,8 | — | 0,8 % | 8 дек. 2023 г. |
39Наблюдать | CVE-2023-51840Эксплойта нет | DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.html-js · doracms · CWE-798 | Критическая9,8 | — | 0,6 % | 29 янв. 2024 г. |
35Наблюдать | CVE-2024-28715Proof of concept | Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 functiohtml-js · doracms · CWE-79 | Высокая8,8 | — | 1,1 % | 19 мар. 2024 г. |
30Наблюдать | CVE-2020-18220Эксплойта нет | Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt ohtml-js · doracms · CWE-326 | Высокая7,5 | — | 0,4 % | 20 мая 2021 г. |
22Наблюдать | CVE-2026-3794Эксплойта нет | doramart DoraCMS Email API send improper authenticationhtml-js · doracms · CWE-287 | Средняя5,5 | — | 1,0 % | 8 мар. 2026 г. |
21Наблюдать | CVE-2018-16622Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web html-js · doracms · CWE-79 | Средняя5,4 | — | 0,8 % | 6 сент. 2018 г. |
21Наблюдать | CVE-2023-49444Эксплойта нет | An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image filhtml-js · doracms · CWE-79 | Средняя5,4 | — | 0,5 % | 8 дек. 2023 г. |
19Наблюдать | CVE-2022-25464Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrarhtml-js · doracms · CWE-79 | Средняя4,8 | — | 0,4 % | 20 мар. 2022 г. |
8Наблюдать | CVE-2026-3795Эксплойта нет | doramart DoraCMS v1.js createFileBypath path traversalhtml-js · doracms · CWE-22 | Низкая2,1 | — | 0,8 % | 8 мар. 2026 г. |
- CVE-2022-3514739Наблюдать
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %html-js · doracms17 авг. 2022 г.
- CVE-2023-4944339Наблюдать
DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %html-js · doracms8 дек. 2023 г.
- CVE-2023-5184039Наблюдать
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %html-js · doracms29 янв. 2024 г.
- CVE-2024-2871535Наблюдать
Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 functio
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %html-js · doracms19 мар. 2024 г.
- CVE-2020-1822030Наблюдать
Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt o
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %html-js · doracms20 мая 2021 г.
- CVE-2026-379422Наблюдать
doramart DoraCMS Email API send improper authentication
СредняяCVSS 5,5Эксплойта нетEPSS 1 %html-js · doracms8 мар. 2026 г.
- CVE-2018-1662221Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web
СредняяCVSS 5,4Эксплойта нетEPSS 1 %html-js · doracms6 сент. 2018 г.
- CVE-2023-4944421Наблюдать
An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image fil
СредняяCVSS 5,4Эксплойта нетEPSS 1 %html-js · doracms8 дек. 2023 г.
- CVE-2022-2546419Наблюдать
A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrar
СредняяCVSS 4,8Эксплойта нетEPSS 0 %html-js · doracms20 мар. 2022 г.
- CVE-2026-37958Наблюдать
doramart DoraCMS v1.js createFileBypath path traversal
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %html-js · doracms8 мар. 2026 г.