html-js kayıtları
html-js üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-326 Inadequate Encryption Strength1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-35147İstismar yok | DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.html-js · doracms · CWE-200 | Kritik9,8 | — | %1,5 | 17 Ağu 2022 |
39İzleyin | CVE-2023-49443İstismar yok | DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords.html-js · doracms · CWE-307 | Kritik9,8 | — | %0,8 | 8 Ara 2023 |
39İzleyin | CVE-2023-51840İstismar yok | DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.html-js · doracms · CWE-798 | Kritik9,8 | — | %0,6 | 29 Oca 2024 |
35İzleyin | CVE-2024-28715Kavram kanıtı | Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 functiohtml-js · doracms · CWE-79 | Yüksek8,8 | — | %1,1 | 19 Mar 2024 |
30İzleyin | CVE-2020-18220İstismar yok | Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt ohtml-js · doracms · CWE-326 | Yüksek7,5 | — | %0,4 | 20 May 2021 |
22İzleyin | CVE-2026-3794İstismar yok | doramart DoraCMS Email API send improper authenticationhtml-js · doracms · CWE-287 | Orta5,5 | — | %1,0 | 8 Mar 2026 |
21İzleyin | CVE-2018-16622İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web html-js · doracms · CWE-79 | Orta5,4 | — | %0,8 | 6 Eyl 2018 |
21İzleyin | CVE-2023-49444İstismar yok | An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image filhtml-js · doracms · CWE-79 | Orta5,4 | — | %0,5 | 8 Ara 2023 |
19İzleyin | CVE-2022-25464İstismar yok | A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrarhtml-js · doracms · CWE-79 | Orta4,8 | — | %0,4 | 20 Mar 2022 |
8İzleyin | CVE-2026-3795İstismar yok | doramart DoraCMS v1.js createFileBypath path traversalhtml-js · doracms · CWE-22 | Düşük2,1 | — | %0,8 | 8 Mar 2026 |
- CVE-2022-3514739İzleyin
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
KritikCVSS 9,8İstismar yokEPSS %1html-js · doracms17 Ağu 2022
- CVE-2023-4944339İzleyin
DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords.
KritikCVSS 9,8İstismar yokEPSS %1html-js · doracms8 Ara 2023
- CVE-2023-5184039İzleyin
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
KritikCVSS 9,8İstismar yokEPSS %1html-js · doracms29 Oca 2024
- CVE-2024-2871535İzleyin
Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 functio
YüksekCVSS 8,8Kavram kanıtıEPSS %1html-js · doracms19 Mar 2024
- CVE-2020-1822030İzleyin
Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt o
YüksekCVSS 7,5İstismar yokEPSS %0html-js · doracms20 May 2021
- CVE-2026-379422İzleyin
doramart DoraCMS Email API send improper authentication
OrtaCVSS 5,5İstismar yokEPSS %1html-js · doracms8 Mar 2026
- CVE-2018-1662221İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web
OrtaCVSS 5,4İstismar yokEPSS %1html-js · doracms6 Eyl 2018
- CVE-2023-4944421İzleyin
An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image fil
OrtaCVSS 5,4İstismar yokEPSS %1html-js · doracms8 Ara 2023
- CVE-2022-2546419İzleyin
A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrar
OrtaCVSS 4,8İstismar yokEPSS %0html-js · doracms20 Mar 2022
- CVE-2026-37958İzleyin
doramart DoraCMS v1.js createFileBypath path traversal
DüşükCVSS 2,1İstismar yokEPSS %1html-js · doracms8 Mar 2026