Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
18048.6%CRITICAL

Related CVEs

8
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2026-3795A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v1.js. Performing a manipulation results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.LOW2.146.8%Mar 9, 2026
CVE-2026-3794A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.MEDIUM5.546.6%Mar 9, 2026
CVE-2024-28715Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.HIGH8.860.7%Mar 19, 2024
CVE-2023-51840DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.CRITICAL9.845.3%Jan 29, 2024
CVE-2023-49444An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar.MEDIUM5.439.6%Dec 8, 2023
CVE-2023-49443DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack.CRITICAL9.852.4%Dec 8, 2023
CVE-2022-35147DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.CRITICAL9.8Aug 17, 2022
CVE-2022-25464A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.MEDIUM4.8Mar 20, 2022