Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-3042 In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS … Dotcms Mitigation only Fix from $1,6002023-10-17 MEDIUM 5.4 CVE-2020-17542 Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail"… Dotcms No fix yet Fix from $1,6002021-04-23 MEDIUM 6.1 CVE-2019-11846 /servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection. Dotcms No fix yet Fix from $1,6002019-05-14 MEDIUM 6.1 CVE-2018-16980 dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters. Dotcms No fix yet Fix from $1,6002018-09-12 MEDIUM 5.4 CVE-2017-15219 The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, … Dotcms No fix yet Fix from $1,6002017-10-10 MEDIUM 6.1 CVE-2017-6003 dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields. Dotcms Mitigation only Fix from $1,6002017-03-27 MEDIUM 6.1 CVE-2017-5876 XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter. Dotcms No fix yet Fix from $1,6002017-02-06 MEDIUM 6.1 CVE-2017-5877 XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter. Dotcms No fix yet Fix from $1,6002017-02-06 MEDIUM 5.4 CVE-2017-5875 XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter. Dotcms No fix yet Fix from $1,6002017-02-06 HIGH 7.5 CVE-2016-8600 In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later. Dotcms No fix yet Fix from $1,9502016-10-28 MEDIUM 6.0 CVE-2012-1826 dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template. Dotcms Mitigation only Fix from $1,6002012-06-08