Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dotcms MEDIUM 6.1
CVE-2017-5877

XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.

No fix yet
Fix from $1,600 2017-02-06
Dotcms MEDIUM 5.4
CVE-2017-5875

XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.

No fix yet
Fix from $1,600 2017-02-06
Dotcms CRITICAL 9.8
CVE-2016-2355

SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter…

Fix: after 3.3.1
Fix from $2,300 2016-12-19
Dotcms HIGH 8.8
CVE-2016-8908

SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitra…

Fix: after 3.3
Fix from $1,950 2016-11-14
Dotcms HIGH 8.8
CVE-2016-8907

SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arb…

Fix: after 3.3
Fix from $1,950 2016-11-14
Dotcms HIGH 8.8
CVE-2016-8906

SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitr…

Fix: after 3.3
Fix from $1,950 2016-11-14
Dotcms HIGH 8.8
CVE-2016-8905

SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands vi…

Fix: after 3.3
Fix from $1,950 2016-11-14
Dotcms HIGH 8.8
CVE-2016-8903

SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute ar…

Fix: after 3.3
Fix from $1,950 2016-11-14
Dotcms HIGH 8.8
CVE-2016-8904

SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute a…

Fix: after 3.3
Fix from $1,950 2016-11-14
Dotcms CRITICAL 9.8
CVE-2016-8902

SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQ…

Fix: after 3.3
Fix from $2,300 2016-11-14
Dotcms HIGH 7.5
CVE-2016-8600

In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.

No fix yet
Fix from $1,950 2016-10-28
Dotcms HIGH 7.5
CVE-2016-4803

CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRL…

Fix: after 3.3.1
Fix from $1,950 2016-06-30
Dotcms HIGH 7.2
CVE-2016-4040

SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orde…

Fix: after 3.3.1
Fix from $1,950 2016-04-19
Dotcms MEDIUM 6.5
CVE-2016-3688

SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/p…

Fix: after 3.3.1
Fix from $1,600 2016-04-19
Dotcms MEDIUM 6.0
CVE-2012-1826

dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.

Mitigation only
Fix from $1,600 2012-06-08