📦 Dotcms

by Dotcms

🔍 What is Dotcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-19138

CRITICAL CVSS 9.8 Sep 8, 2021

This vulnerability allows remote attackers to upload malicious files to DotCMS servers, leading to arbitrary code execution. Attackers can exploit this by uploading dangerous file types through the CM...

CVE-2022-45782

HIGH CVSS 8.8 Feb 1, 2023

This vulnerability in dotCMS allows attackers to predict password reset tokens due to cryptographically insecure random generation. Attackers can use predictable tokens to reset user passwords and tak...

CVE-2024-3938

MEDIUM CVSS 5.4 Jul 25, 2024

This vulnerability allows attackers to inject HTML content into the password reset page via URL parameters. This affects all users accessing the vulnerable login page, potentially enabling phishing at...