Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2023-53952
Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension…
Dotclear
No fix yet
HIGH 8.8
CVE-2024-58281
Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media uplo…
Dotclear
No fix yet
MEDIUM 6.1
CVE-2024-27626
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of…
Dotclear
No fix yet
MEDIUM 5.4
CVE-2018-16358
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated …
Dotclear
after 2.14.1
MEDIUM 5.4
CVE-2018-5689
Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTM…
Dotclear
Mitigation only
MEDIUM 5.4
CVE-2018-5690
Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HT…
Dotclear
Mitigation only
MEDIUM 6.1
CVE-2017-6446
XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.
Dotclear
Patch available
HIGH 8.8
CVE-2015-8832
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage th…
Dotclear
after 2.8.1
MEDIUM 6.1
CVE-2015-8831
Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web script or HTM…
Dotclear
after 2.8.1
HIGH 8.8
CVE-2016-7902
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to…
Dotclear
after 2.10.2
MEDIUM 5.4
CVE-2016-9891
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inj…
Dotclear
after 2.10.4
MEDIUM 6.1
CVE-2016-6523
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web scrip…
Dotclear
after 2.9.1
HIGH 7.2
CVE-2016-9268EPSS 5%
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote au…
Dotclear
after 2.10.4
MEDIUM 6.0
CVE-2014-3782
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote aut…
Dotclear
after 2.6.2
MEDIUM 5.8
CVE-2014-3781
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty pa…
Dotclear
after 2.6.2
MEDIUM 6.0
CVE-2014-3783
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission …
Dotclear
after 2.6.2
HIGH 7.5
CVE-2014-1613
Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected p…
Dotclear
after 2.6.1
HIGH 7.5
CVE-2011-5083
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uplo…
Dotclear
No fix yet
MEDIUM 6.5
CVE-2011-1584
The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allo…
Dotclear
after 2.2.2
HIGH 9.3
CVE-2008-3232
Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary co…
Dotclear
after 1.2.7
MEDIUM 5.0
CVE-2006-3938
DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrir…
Dotclear
Mitigation only
MEDIUM 5.1
CVE-2006-2866
PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via…
Dotclear
No fix yet
HIGH 7.5
CVE-2005-3963
SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter…
Dotclear
Patch available
HIGH 10.0
CVE-2005-3957
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.
Dotclear
Patch available