Dotcms / Dotcms Core
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-8054 | Unauthenticated SQL Injection in dotCMS Publish Audit API | CRITICAL | 10.0 | May 27, 2026 |
| CVE-2024-4447 | In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dw… | CRITICAL | 9.9 | Jul 26, 2024 |
| CVE-2024-3938 | The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated… | MEDIUM | 6.1 | Jul 25, 2024 |
| CVE-2024-3165 | Database Credential Exposure in the Logs | MEDIUM | 4.5 | Apr 1, 2024 |
| CVE-2024-3164 | In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone wi… | MEDIUM | 4.5 | Apr 1, 2024 |
| CVE-2023-3042 | CNA SHORTNAME: dotCMSORG UUID: 5b9d93f2-25c7-46b4-ab60-d201718c9dd8 | MEDIUM | 6.1 | Oct 17, 2023 |
Showing 1 to 5 of 5 CVEs