Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2025-11165 A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to byp… Dotcms 24.12.27 / 25.07.10+ Fix from $2,3002026-02-24 MEDIUM 6.1 CVE-2024-3938 The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be d… Dotcms 23.01.18 / 24.05.31+ Fix from $1,6002024-07-25 MEDIUM 6.1 CVE-2023-3042 In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS … Dotcms Mitigation only Fix from $1,6002023-10-17 MEDIUM 5.3 CVE-2022-37034 In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done… Dotcms 21.06.12 / 22.03.4+ Fix from $1,6002023-02-01 HIGH 8.8 CVE-2022-45782 An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm f… Dotcms after 21.10.1 Fix from $1,9502023-02-01 MEDIUM 6.5 CVE-2022-37033 In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to loca… Dotcms 21.06.12 / 22.03.4+ Fix from $1,6002023-02-01 MEDIUM 6.5 CVE-2022-45783EPSS 8% An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote C… Dotcms after 22.10.1 Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2022-35740 dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using a semicolon in a URL to intro… Dotcms 5.3.8.12 / 21.06.9+ Fix from $1,6002022-11-10 MEDIUM 6.1 CVE-2022-37431 A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin portal when the configuration has … Dotcms after 22.06 Fix from $1,6002022-08-05 CRITICAL 9.8 CVE-2022-26352 KEVEPSS 91% An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose fil… Dotcms after 22.02 Fix from $2,3002022-07-17 CRITICAL 9.8 CVE-2020-19138EPSS 6% Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src… Dotcms after 5.2.3 Fix from $2,3002021-09-08 HIGH 8.8 CVE-2020-18875 Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocit… Dotcms 5.1.0+ Fix from $1,9502021-08-18 MEDIUM 5.4 CVE-2020-17542 Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail"… Dotcms No fix yet Fix from $1,6002021-04-23 HIGH 8.8 CVE-2020-27848 dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used t… Dotcms 20.10.1+ Fix from $1,9502020-12-30 CRITICAL 9.8 CVE-2020-6754EPSS 95% dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $… Dotcms 5.2.4+ Fix from $2,3002020-02-05 HIGH 7.2 CVE-2019-12872 dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp. Dotcms 5.1.6+ Fix from $1,9502019-06-18 MEDIUM 6.1 CVE-2019-11846 /servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection. Dotcms No fix yet Fix from $1,6002019-05-14 MEDIUM 6.1 CVE-2018-17422 dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp… Dotcms 5.0.2+ Fix from $1,6002019-03-07 MEDIUM 5.4 CVE-2018-19554 An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcm… Dotcms after 5.0.3 Fix from $1,6002018-11-26 MEDIUM 6.1 CVE-2018-16980 dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters. Dotcms No fix yet Fix from $1,6002018-09-12 HIGH 8.8 CVE-2017-3187 The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a … Dotcms after 3.7.1 Fix from $1,9502018-07-24 HIGH 8.1 CVE-2017-3189EPSS 7% The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When… Dotcms after 3.7.1 Fix from $1,9502018-07-24 MEDIUM 6.5 CVE-2017-3188 The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundl… Dotcms after 3.7.1 Fix from $1,6002018-07-24 HIGH 7.2 CVE-2016-10007 SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators … Dotcms 3.7.2 / 4.1.1+ Fix from $1,9502018-02-19 HIGH 7.2 CVE-2016-10008 SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated adm… Dotcms 3.7.2 / 4.1.1+ Fix from $1,9502018-02-19 MEDIUM 5.4 CVE-2017-15219 The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, … Dotcms No fix yet Fix from $1,6002017-10-10 HIGH 7.2 CVE-2017-11466EPSS 8% Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrato… Dotcms Patch available Fix from $1,9502017-07-20 MEDIUM 6.1 CVE-2017-6003 dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields. Dotcms Mitigation only Fix from $1,6002017-03-27 CRITICAL 9.8 CVE-2017-5344EPSS 6% An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet pe… Dotcms after 3.6.1 Fix from $2,3002017-02-17 MEDIUM 6.1 CVE-2017-5876 XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter. Dotcms No fix yet Fix from $1,6002017-02-06