Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-53952 Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension… Dotclear No fix yet Fix from $1,9502025-12-19 HIGH 8.8 CVE-2024-58281 Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media uplo… Dotclear No fix yet Fix from $1,9502025-12-10 MEDIUM 6.1 CVE-2024-27626 A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of… Dotclear No fix yet Fix from $1,6002024-03-21 MEDIUM 5.4 CVE-2018-5689 Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTM… Dotclear Mitigation only Fix from $1,6002018-01-14 MEDIUM 5.4 CVE-2018-5690 Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HT… Dotclear Mitigation only Fix from $1,6002018-01-14 HIGH 7.5 CVE-2011-5083 Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uplo… Dotclear No fix yet Fix from $1,9502012-03-19 MEDIUM 5.0 CVE-2006-3938 DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrir… Dotclear Mitigation only Fix from $1,6002006-07-31 MEDIUM 5.1 CVE-2006-2866 PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via… Dotclear No fix yet Fix from $1,6002006-06-06