İçeriğe atla
Noroxi

dotCMS kayıtları

dotcms üreticisine ait 57 yayımlanmış kayıt.

Tüm kayıtlar

57 kayıt
  • An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92

    dotcms · dotcms17 Tem 2022

  • CVE-2020-6754
    67Bu hafta

    dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.

    KritikCVSS 9,8İstismar yokEPSS %95

    dotcms · dotcms5 Şub 2020

  • CVE-2017-5344
    41Planlayın

    An issue was discovered in dotCMS through 3.6.1.

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    dotcms · dotcms17 Şub 2017

  • CVE-2020-19138
    41Planlayın

    Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the compon

    KritikCVSS 9,8İstismar yokEPSS %6

    dotcms · dotcms8 Eyl 2021

  • CVE-2016-8902
    40Planlayın

    SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arb

    KritikCVSS 9,8İstismar yokEPSS %3

    dotcms · dotcms14 Kas 2016

  • CVE-2016-2355
    40Planlayın

    SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName

    KritikCVSS 9,8İstismar yokEPSS %2

    dotcms · dotcms19 Ara 2016

  • CVE-2025-11165
    37İzleyin

    A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileg

    KritikCVSS 9,4İstismar yokEPSS %0

    dotcms · dotcms24 Şub 2026

  • CVE-2016-8906
    36İzleyin

    SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execu

    YüksekCVSS 8,8İstismar yokEPSS %2

    dotcms · dotcms14 Kas 2016

  • CVE-2016-8907
    36İzleyin

    SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to ex

    YüksekCVSS 8,8İstismar yokEPSS %2

    dotcms · dotcms14 Kas 2016

  • CVE-2016-8908
    36İzleyin

    SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execut

    YüksekCVSS 8,8İstismar yokEPSS %2

    dotcms · dotcms14 Kas 2016

  • CVE-2016-8905
    36İzleyin

    SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL co

    YüksekCVSS 8,8İstismar yokEPSS %2

    dotcms · dotcms14 Kas 2016

  • CVE-2020-18875
    36İzleyin

    Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl

    YüksekCVSS 8,8İstismar yokEPSS %2

    dotcms · dotcms18 Ağu 2021

  • CVE-2016-8903
    36İzleyin

    SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to e

    YüksekCVSS 8,8İstismar yokEPSS %2

    dotcms · dotcms14 Kas 2016

  • CVE-2016-8904
    36İzleyin

    SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to

    YüksekCVSS 8,8İstismar yokEPSS %2

    dotcms · dotcms14 Kas 2016

  • CVE-2020-27848
    35İzleyin

    dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter.

    YüksekCVSS 8,8İstismar yokEPSS %1

    dotcms · dotcms30 Ara 2020

  • CVE-2017-3187
    35İzleyin

    The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery

    YüksekCVSS 8,8İstismar yokEPSS %1

    dotcms · dotcms24 Tem 2018

  • CVE-2022-45782
    35İzleyin

    An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1.

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    dotcms · dotcms1 Şub 2023

  • CVE-2017-3189
    34İzleyin

    The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload

    YüksekCVSS 8,1İstismar yokEPSS %6

    dotcms · dotcms24 Tem 2018

  • CVE-2016-4803
    31İzleyin

    CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email header

    YüksekCVSS 7,5İstismar yokEPSS %2

    dotcms · dotcms30 Haz 2016

  • CVE-2016-8600
    31İzleyin

    In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check l

    YüksekCVSS 7,5İstismar yokEPSS %2

    dotcms · dotcms28 Eki 2016

  • CVE-2017-11466
    30İzleyin

    Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated adm

    YüksekCVSS 7,2İstismar yokEPSS %8

    dotcms · dotcms19 Tem 2017

  • CVE-2022-45783
    29İzleyin

    An issue was discovered in dotCMS core 4.x through 22.10.2.

    OrtaCVSS 6,5İstismar yokEPSS %8

    dotcms · dotcms1 Şub 2023

  • CVE-2016-4040
    28İzleyin

    SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via

    YüksekCVSS 7,2İstismar yokEPSS %1

    dotcms · dotcms19 Nis 2016

  • CVE-2019-12872
    28İzleyin

    dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.js

    YüksekCVSS 7,2İstismar yokEPSS %1

    dotcms · dotcms18 Haz 2019

  • CVE-2016-10008
    28İzleyin

    SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenti

    YüksekCVSS 7,2İstismar yokEPSS %1

    dotcms · dotcms19 Şub 2018