Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-53952 Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension… Dotclear No fix yet Fix from $1,9502025-12-19 HIGH 8.8 CVE-2024-58281 Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media uplo… Dotclear No fix yet Fix from $1,9502025-12-10 MEDIUM 6.1 CVE-2024-27626 A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of… Dotclear No fix yet Fix from $1,6002024-03-21 MEDIUM 5.4 CVE-2018-16358 A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated … Dotclear after 2.14.1 Fix from $1,6002018-09-02 MEDIUM 5.4 CVE-2018-5689 Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTM… Dotclear Mitigation only Fix from $1,6002018-01-14 MEDIUM 5.4 CVE-2018-5690 Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HT… Dotclear Mitigation only Fix from $1,6002018-01-14 MEDIUM 6.1 CVE-2017-6446 XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters. Dotclear Patch available Fix from $1,6002017-03-05 HIGH 8.8 CVE-2015-8832 Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage th… Dotclear after 2.8.1 Fix from $1,9502017-02-09 MEDIUM 6.1 CVE-2015-8831 Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web script or HTM… Dotclear after 2.8.1 Fix from $1,6002017-02-09 HIGH 8.8 CVE-2016-7902 Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to… Dotclear after 2.10.2 Fix from $1,9502017-01-04 MEDIUM 5.4 CVE-2016-9891 Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inj… Dotclear after 2.10.4 Fix from $1,6002016-12-29 MEDIUM 6.1 CVE-2016-6523 Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web scrip… Dotclear after 2.9.1 Fix from $1,6002016-12-09 HIGH 7.2 CVE-2016-9268EPSS 5% Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote au… Dotclear after 2.10.4 Fix from $1,9502016-11-10 MEDIUM 6.0 CVE-2014-3782 Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote aut… Dotclear after 2.6.2 Fix from $1,6002014-06-11 MEDIUM 5.8 CVE-2014-3781 The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty pa… Dotclear after 2.6.2 Fix from $1,6002014-06-11 MEDIUM 6.0 CVE-2014-3783 SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission … Dotclear after 2.6.2 Fix from $1,6002014-05-22 HIGH 7.5 CVE-2014-1613 Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected p… Dotclear after 2.6.1 Fix from $1,9502014-05-16 HIGH 7.5 CVE-2011-5083 Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uplo… Dotclear No fix yet Fix from $1,9502012-03-19 MEDIUM 6.5 CVE-2011-1584 The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allo… Dotclear after 2.2.2 Fix from $1,6002011-06-08 HIGH 9.3 CVE-2008-3232 Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary co… Dotclear after 1.2.7 Fix from $1,9502008-07-18 MEDIUM 5.0 CVE-2006-3938 DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrir… Dotclear Mitigation only Fix from $1,6002006-07-31 MEDIUM 5.1 CVE-2006-2866 PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via… Dotclear No fix yet Fix from $1,6002006-06-06 HIGH 7.5 CVE-2005-3963 SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter… Dotclear Patch available Fix from $1,9502005-12-02 HIGH 10.0 CVE-2005-3957 Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors. Dotclear Patch available Fix from $1,9502005-12-01