VYPR

Vendor CVEs

Dotcms

All CVEs

61 total · sorted by risk
  • CVE-2020-35274MedDec 21, 2020
    risk 0.31cvss 4.8epss 0.01

    DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.

  • CVE-2016-3971MedApr 18, 2016
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in lucene_search.jsp in dotCMS before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to c/portal/layout.

  • CVE-2024-3938MedJul 25, 2024
    risk 0.28cvss 5.4epss 0.00

    The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a http://localhost:8082/dotAdmin/#/public/lo…

  • CVE-2024-3165MedApr 1, 2024
    risk 0.22cvss 4.5epss 0.01

    System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.   OWASP Top 10 - A05)…

  • CVE-2024-3164MedApr 1, 2024
    risk 0.22cvss 4.5epss 0.00

    In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, should not have access…

  • CVE-2016-3972LowApr 18, 2016
    risk 0.18cvss 2.7epss 0.01

    Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.

  • CVE-2008-3708Aug 19, 2008
    risk 0.03cvss epss 0.05

    Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot.

  • CVE-2026-16337CriJul 20, 2026
    risk 0.00cvss epss 0.00

    Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then…

  • CVE-2013-3484Apr 2, 2014
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) _loginUserName parameter to application/login/login.html, (2) my_account_login parameter to c/portal_public/login, or (3) email…

  • CVE-2012-1826Jun 8, 2012
    risk 0.00cvss epss 0.02

    dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.

  • CVE-2008-2397May 21, 2008
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

Page 2 of 2