Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2017-5877 XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter. Dotcms No fix yet Fix from $1,6002017-02-06 MEDIUM 5.4 CVE-2017-5875 XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter. Dotcms No fix yet Fix from $1,6002017-02-06 CRITICAL 9.8 CVE-2016-2355 SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter… Dotcms after 3.3.1 Fix from $2,3002016-12-19 HIGH 8.8 CVE-2016-8908 SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitra… Dotcms after 3.3 Fix from $1,9502016-11-14 HIGH 8.8 CVE-2016-8907 SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arb… Dotcms after 3.3 Fix from $1,9502016-11-14 HIGH 8.8 CVE-2016-8906 SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitr… Dotcms after 3.3 Fix from $1,9502016-11-14 HIGH 8.8 CVE-2016-8905 SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands vi… Dotcms after 3.3 Fix from $1,9502016-11-14 HIGH 8.8 CVE-2016-8903 SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute ar… Dotcms after 3.3 Fix from $1,9502016-11-14 HIGH 8.8 CVE-2016-8904 SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute a… Dotcms after 3.3 Fix from $1,9502016-11-14 CRITICAL 9.8 CVE-2016-8902 SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQ… Dotcms after 3.3 Fix from $2,3002016-11-14 HIGH 7.5 CVE-2016-8600 In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later. Dotcms No fix yet Fix from $1,9502016-10-28 HIGH 7.5 CVE-2016-4803 CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRL… Dotcms after 3.3.1 Fix from $1,9502016-06-30 HIGH 7.2 CVE-2016-4040 SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orde… Dotcms after 3.3.1 Fix from $1,9502016-04-19 MEDIUM 6.5 CVE-2016-3688 SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/p… Dotcms after 3.3.1 Fix from $1,6002016-04-19 MEDIUM 6.0 CVE-2012-1826 dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template. Dotcms Mitigation only Fix from $1,6002012-06-08