Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dotclear HIGH 8.8
CVE-2023-53952

Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension…

No fix yet
Fix from $1,950 2025-12-19
Dotclear HIGH 8.8
CVE-2024-58281

Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media uplo…

No fix yet
Fix from $1,950 2025-12-10
Dotclear MEDIUM 6.1
CVE-2024-27626

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of…

No fix yet
Fix from $1,600 2024-03-21
Dotclear MEDIUM 5.4
CVE-2018-16358

A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated …

Fix: after 2.14.1
Fix from $1,600 2018-09-02
Dotclear MEDIUM 5.4
CVE-2018-5689

Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTM…

Mitigation only
Fix from $1,600 2018-01-14
Dotclear MEDIUM 5.4
CVE-2018-5690

Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HT…

Mitigation only
Fix from $1,600 2018-01-14
Dotclear MEDIUM 6.1
CVE-2017-6446

XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.

Patch available
Fix from $1,600 2017-03-05
Dotclear HIGH 8.8
CVE-2015-8832

Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage th…

Fix: after 2.8.1
Fix from $1,950 2017-02-09
Dotclear MEDIUM 6.1
CVE-2015-8831

Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web script or HTM…

Fix: after 2.8.1
Fix from $1,600 2017-02-09
Dotclear HIGH 8.8
CVE-2016-7902

Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to…

Fix: after 2.10.2
Fix from $1,950 2017-01-04
Dotclear MEDIUM 5.4
CVE-2016-9891

Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inj…

Fix: after 2.10.4
Fix from $1,600 2016-12-29
Dotclear MEDIUM 6.1
CVE-2016-6523

Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web scrip…

Fix: after 2.9.1
Fix from $1,600 2016-12-09
Dotclear HIGH 7.2
CVE-2016-9268EPSS 5%

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote au…

Fix: after 2.10.4
Fix from $1,950 2016-11-10
Dotclear MEDIUM 6.0
CVE-2014-3782

Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote aut…

Fix: after 2.6.2
Fix from $1,600 2014-06-11
Dotclear MEDIUM 5.8
CVE-2014-3781

The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty pa…

Fix: after 2.6.2
Fix from $1,600 2014-06-11
Dotclear MEDIUM 6.0
CVE-2014-3783

SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission …

Fix: after 2.6.2
Fix from $1,600 2014-05-22
Dotclear HIGH 7.5
CVE-2014-1613

Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected p…

Fix: after 2.6.1
Fix from $1,950 2014-05-16
Dotclear HIGH 7.5
CVE-2011-5083

Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uplo…

No fix yet
Fix from $1,950 2012-03-19
Dotclear MEDIUM 6.5
CVE-2011-1584

The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allo…

Fix: after 2.2.2
Fix from $1,600 2011-06-08
Dotclear HIGH 9.3
CVE-2008-3232

Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary co…

Fix: after 1.2.7
Fix from $1,950 2008-07-18
Dotclear MEDIUM 5.0
CVE-2006-3938

DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrir…

Mitigation only
Fix from $1,600 2006-07-31
Dotclear MEDIUM 5.1
CVE-2006-2866

PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via…

No fix yet
Fix from $1,600 2006-06-06
Dotclear HIGH 7.5
CVE-2005-3963

SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter…

Patch available
Fix from $1,950 2005-12-02
Dotclear HIGH 10.0
CVE-2005-3957

Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.

Patch available
Fix from $1,950 2005-12-01