Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dotcms MEDIUM 6.1
CVE-2023-3042

In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS …

Mitigation only
Fix from $1,600 2023-10-17
Dotcms MEDIUM 5.4
CVE-2020-17542

Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail"…

No fix yet
Fix from $1,600 2021-04-23
Dotcms MEDIUM 6.1
CVE-2019-11846

/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.

No fix yet
Fix from $1,600 2019-05-14
Dotcms MEDIUM 6.1
CVE-2018-16980

dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.

No fix yet
Fix from $1,600 2018-09-12
Dotcms MEDIUM 5.4
CVE-2017-15219

The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, …

No fix yet
Fix from $1,600 2017-10-10
Dotcms MEDIUM 6.1
CVE-2017-6003

dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.

Mitigation only
Fix from $1,600 2017-03-27
Dotcms MEDIUM 6.1
CVE-2017-5876

XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.

No fix yet
Fix from $1,600 2017-02-06
Dotcms MEDIUM 6.1
CVE-2017-5877

XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.

No fix yet
Fix from $1,600 2017-02-06
Dotcms MEDIUM 5.4
CVE-2017-5875

XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.

No fix yet
Fix from $1,600 2017-02-06
Dotcms HIGH 7.5
CVE-2016-8600

In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.

No fix yet
Fix from $1,950 2016-10-28
Dotcms MEDIUM 6.0
CVE-2012-1826

dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.

Mitigation only
Fix from $1,600 2012-06-08