dotCMS kayıtları
dotcms üreticisine ait 57 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,8
- Silahlaştırılmış
- 1 · %1,8
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %5,3
- Yayından KEV’e ortanca
- 39 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')19
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-284 Improper Access Control1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
57 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
96Hemen | CVE-2022-26352Silahlaştırılmış | An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02.dotcms · dotcms | Kritik9,8 | KEV | %91,6 | 17 Tem 2022 |
67Bu hafta | CVE-2020-6754İstismar yok | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.dotcms · dotcms · CWE-22 | Kritik9,8 | — | %94,8 | 5 Şub 2020 |
41Planlayın | CVE-2017-5344Kavram kanıtı | An issue was discovered in dotCMS through 3.6.1.dotcms · dotcms · CWE-89 | Kritik9,8 | — | %6,3 | 17 Şub 2017 |
41Planlayın | CVE-2020-19138İstismar yok | Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the compondotcms · dotcms · CWE-434 | Kritik9,8 | — | %5,7 | 8 Eyl 2021 |
40Planlayın | CVE-2016-8902İstismar yok | SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbdotcms · dotcms · CWE-89 | Kritik9,8 | — | %2,8 | 14 Kas 2016 |
40Planlayın | CVE-2016-2355İstismar yok | SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName dotcms · dotcms · CWE-89 | Kritik9,8 | — | %2,1 | 19 Ara 2016 |
37İzleyin | CVE-2025-11165İstismar yok | A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privilegdotcms · dotcms · CWE-89 | Kritik9,4 | — | %0,3 | 24 Şub 2026 |
36İzleyin | CVE-2016-8906İstismar yok | SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execudotcms · dotcms · CWE-89 | Yüksek8,8 | — | %2,0 | 14 Kas 2016 |
36İzleyin | CVE-2016-8907İstismar yok | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to exdotcms · dotcms · CWE-89 | Yüksek8,8 | — | %2,0 | 14 Kas 2016 |
36İzleyin | CVE-2016-8908İstismar yok | SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to executdotcms · dotcms · CWE-89 | Yüksek8,8 | — | %2,0 | 14 Kas 2016 |
36İzleyin | CVE-2016-8905İstismar yok | SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL codotcms · dotcms · CWE-89 | Yüksek8,8 | — | %2,0 | 14 Kas 2016 |
36İzleyin | CVE-2020-18875İstismar yok | Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtldotcms · dotcms · CWE-74 | Yüksek8,8 | — | %2,0 | 18 Ağu 2021 |
36İzleyin | CVE-2016-8903İstismar yok | SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to edotcms · dotcms · CWE-89 | Yüksek8,8 | — | %1,9 | 14 Kas 2016 |
36İzleyin | CVE-2016-8904İstismar yok | SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to dotcms · dotcms · CWE-89 | Yüksek8,8 | — | %1,9 | 14 Kas 2016 |
35İzleyin | CVE-2020-27848İstismar yok | dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter.dotcms · dotcms · CWE-89 | Yüksek8,8 | — | %1,2 | 30 Ara 2020 |
35İzleyin | CVE-2017-3187İstismar yok | The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgerydotcms · dotcms · CWE-352 | Yüksek8,8 | — | %1,1 | 24 Tem 2018 |
35İzleyin | CVE-2022-45782Kavram kanıtı | An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1.dotcms · dotcms · CWE-338 | Yüksek8,8 | — | %0,6 | 1 Şub 2023 |
34İzleyin | CVE-2017-3189İstismar yok | The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file uploaddotcms · dotcms · CWE-434 | Yüksek8,1 | — | %6,5 | 24 Tem 2018 |
31İzleyin | CVE-2016-4803İstismar yok | CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headerdotcms · dotcms | Yüksek7,5 | — | %2,2 | 30 Haz 2016 |
31İzleyin | CVE-2016-8600İstismar yok | In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check ldotcms · dotcms · CWE-254 | Yüksek7,5 | — | %1,8 | 28 Eki 2016 |
30İzleyin | CVE-2017-11466İstismar yok | Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated admdotcms · dotcms · CWE-434 | Yüksek7,2 | — | %7,7 | 19 Tem 2017 |
29İzleyin | CVE-2022-45783İstismar yok | An issue was discovered in dotCMS core 4.x through 22.10.2.dotcms · dotcms · CWE-22 | Orta6,5 | — | %8,5 | 1 Şub 2023 |
28İzleyin | CVE-2016-4040İstismar yok | SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands viadotcms · dotcms · CWE-89 | Yüksek7,2 | — | %1,3 | 19 Nis 2016 |
28İzleyin | CVE-2019-12872İstismar yok | dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsdotcms · dotcms · CWE-89 | Yüksek7,2 | — | %1,3 | 18 Haz 2019 |
28İzleyin | CVE-2016-10008İstismar yok | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authentidotcms · dotcms · CWE-89 | Yüksek7,2 | — | %1,3 | 19 Şub 2018 |
- CVE-2022-2635296Hemen
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92dotcms · dotcms17 Tem 2022
- CVE-2020-675467Bu hafta
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control.
KritikCVSS 9,8İstismar yokEPSS %95dotcms · dotcms5 Şub 2020
- CVE-2017-534441Planlayın
An issue was discovered in dotCMS through 3.6.1.
KritikCVSS 9,8Kavram kanıtıEPSS %6dotcms · dotcms17 Şub 2017
- CVE-2020-1913841Planlayın
Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the compon
KritikCVSS 9,8İstismar yokEPSS %6dotcms · dotcms8 Eyl 2021
- CVE-2016-890240Planlayın
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arb
KritikCVSS 9,8İstismar yokEPSS %3dotcms · dotcms14 Kas 2016
- CVE-2016-235540Planlayın
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName
KritikCVSS 9,8İstismar yokEPSS %2dotcms · dotcms19 Ara 2016
- CVE-2025-1116537İzleyin
A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileg
KritikCVSS 9,4İstismar yokEPSS %0dotcms · dotcms24 Şub 2026
- CVE-2016-890636İzleyin
SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execu
YüksekCVSS 8,8İstismar yokEPSS %2dotcms · dotcms14 Kas 2016
- CVE-2016-890736İzleyin
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to ex
YüksekCVSS 8,8İstismar yokEPSS %2dotcms · dotcms14 Kas 2016
- CVE-2016-890836İzleyin
SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execut
YüksekCVSS 8,8İstismar yokEPSS %2dotcms · dotcms14 Kas 2016
- CVE-2016-890536İzleyin
SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL co
YüksekCVSS 8,8İstismar yokEPSS %2dotcms · dotcms14 Kas 2016
- CVE-2020-1887536İzleyin
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl
YüksekCVSS 8,8İstismar yokEPSS %2dotcms · dotcms18 Ağu 2021
- CVE-2016-890336İzleyin
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to e
YüksekCVSS 8,8İstismar yokEPSS %2dotcms · dotcms14 Kas 2016
- CVE-2016-890436İzleyin
SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to
YüksekCVSS 8,8İstismar yokEPSS %2dotcms · dotcms14 Kas 2016
- CVE-2020-2784835İzleyin
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter.
YüksekCVSS 8,8İstismar yokEPSS %1dotcms · dotcms30 Ara 2020
- CVE-2017-318735İzleyin
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery
YüksekCVSS 8,8İstismar yokEPSS %1dotcms · dotcms24 Tem 2018
- CVE-2022-4578235İzleyin
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1.
YüksekCVSS 8,8Kavram kanıtıEPSS %1dotcms · dotcms1 Şub 2023
- CVE-2017-318934İzleyin
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload
YüksekCVSS 8,1İstismar yokEPSS %6dotcms · dotcms24 Tem 2018
- CVE-2016-480331İzleyin
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email header
YüksekCVSS 7,5İstismar yokEPSS %2dotcms · dotcms30 Haz 2016
- CVE-2016-860031İzleyin
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check l
YüksekCVSS 7,5İstismar yokEPSS %2dotcms · dotcms28 Eki 2016
- CVE-2017-1146630İzleyin
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated adm
YüksekCVSS 7,2İstismar yokEPSS %8dotcms · dotcms19 Tem 2017
- CVE-2022-4578329İzleyin
An issue was discovered in dotCMS core 4.x through 22.10.2.
OrtaCVSS 6,5İstismar yokEPSS %8dotcms · dotcms1 Şub 2023
- CVE-2016-404028İzleyin
SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via
YüksekCVSS 7,2İstismar yokEPSS %1dotcms · dotcms19 Nis 2016
- CVE-2019-1287228İzleyin
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.js
YüksekCVSS 7,2İstismar yokEPSS %1dotcms · dotcms18 Haz 2019
- CVE-2016-1000828İzleyin
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenti
YüksekCVSS 7,2İstismar yokEPSS %1dotcms · dotcms19 Şub 2018