Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dotclear HIGH 8.8
CVE-2023-53952

Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension…

No fix yet
Fix from $1,950 2025-12-19
Dotclear HIGH 8.8
CVE-2024-58281

Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media uplo…

No fix yet
Fix from $1,950 2025-12-10
Dotclear MEDIUM 6.1
CVE-2024-27626

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of…

No fix yet
Fix from $1,600 2024-03-21
Dotclear MEDIUM 5.4
CVE-2018-5689

Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTM…

Mitigation only
Fix from $1,600 2018-01-14
Dotclear MEDIUM 5.4
CVE-2018-5690

Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HT…

Mitigation only
Fix from $1,600 2018-01-14
Dotclear HIGH 7.5
CVE-2011-5083

Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uplo…

No fix yet
Fix from $1,950 2012-03-19
Dotclear MEDIUM 5.0
CVE-2006-3938

DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrir…

Mitigation only
Fix from $1,600 2006-07-31
Dotclear MEDIUM 5.1
CVE-2006-2866

PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via…

No fix yet
Fix from $1,600 2006-06-06