Dotcms

Dotcms

59 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.55%
  • Veröffentlicht 06.02.2017 15:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.

  • EPSS 2.1%
  • Veröffentlicht 19.12.2016 22:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.

Exploit
  • EPSS 2%
  • Veröffentlicht 14.11.2016 23:20:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

Exploit
  • EPSS 2%
  • Veröffentlicht 14.11.2016 23:20:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

Exploit
  • EPSS 2%
  • Veröffentlicht 14.11.2016 23:20:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

Exploit
  • EPSS 2%
  • Veröffentlicht 14.11.2016 23:20:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.

Exploit
  • EPSS 1.94%
  • Veröffentlicht 14.11.2016 23:20:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

Exploit
  • EPSS 1.94%
  • Veröffentlicht 14.11.2016 23:20:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

Exploit
  • EPSS 2.75%
  • Veröffentlicht 14.11.2016 23:20:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.

Exploit
  • EPSS 1.75%
  • Veröffentlicht 28.10.2016 15:59:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.