Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.9
CVE-2025-11165
A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to byp…
Dotcms
24.12.27 / 25.07.10+
MEDIUM 6.1
CVE-2024-3938
The "reset password" login page accepted an HTML injection via URL parameters.
This has already been rectified via patch, and as such it cannot be d…
Dotcms
23.01.18 / 24.05.31+
MEDIUM 6.1
CVE-2023-3042
In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS …
Dotcms
Mitigation only
MEDIUM 5.3
CVE-2022-37034
In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done…
Dotcms
21.06.12 / 22.03.4+
HIGH 8.8
CVE-2022-45782
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm f…
Dotcms
after 21.10.1
MEDIUM 6.5
CVE-2022-37033
In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to loca…
Dotcms
21.06.12 / 22.03.4+
MEDIUM 6.5
CVE-2022-45783EPSS 8%
An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote C…
Dotcms
after 22.10.1
MEDIUM 6.1
CVE-2022-35740
dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using a semicolon in a URL to intro…
Dotcms
5.3.8.12 / 21.06.9+
MEDIUM 6.1
CVE-2022-37431
A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin portal when the configuration has …
Dotcms
after 22.06
CRITICAL 9.8
CVE-2022-26352 KEVEPSS 91%
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose fil…
Dotcms
after 22.02
CRITICAL 9.8
CVE-2020-19138EPSS 6%
Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src…
Dotcms
after 5.2.3
HIGH 8.8
CVE-2020-18875
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocit…
Dotcms
5.1.0+
MEDIUM 5.4
CVE-2020-17542
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail"…
Dotcms
No fix yet
HIGH 8.8
CVE-2020-27848
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used t…
Dotcms
20.10.1+
CRITICAL 9.8
CVE-2020-6754EPSS 95%
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $…
Dotcms
5.2.4+
HIGH 7.2
CVE-2019-12872
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.
Dotcms
5.1.6+
MEDIUM 6.1
CVE-2019-11846
/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.
Dotcms
No fix yet
MEDIUM 6.1
CVE-2018-17422
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp…
Dotcms
5.0.2+
MEDIUM 5.4
CVE-2018-19554
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcm…
Dotcms
after 5.0.3
MEDIUM 6.1
CVE-2018-16980
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
Dotcms
No fix yet
HIGH 8.8
CVE-2017-3187
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a …
Dotcms
after 3.7.1
HIGH 8.1
CVE-2017-3189EPSS 7%
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When…
Dotcms
after 3.7.1
MEDIUM 6.5
CVE-2017-3188
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundl…
Dotcms
after 3.7.1
HIGH 7.2
CVE-2016-10007
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators …
Dotcms
3.7.2 / 4.1.1+
HIGH 7.2
CVE-2016-10008
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated adm…
Dotcms
3.7.2 / 4.1.1+
MEDIUM 5.4
CVE-2017-15219
The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, …
Dotcms
No fix yet
HIGH 7.2
CVE-2017-11466EPSS 8%
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrato…
Dotcms
Patch available
MEDIUM 6.1
CVE-2017-6003
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.
Dotcms
Mitigation only
CRITICAL 9.8
CVE-2017-5344EPSS 6%
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet pe…
Dotcms
after 3.6.1
MEDIUM 6.1
CVE-2017-5876
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.
Dotcms
No fix yet