VendorsDouCodouphp1.6
Vulnerabilities

DouCo DouPHP 1.5 20190516 1.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-24131
DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.
Published 2022-03-30 · Modified
6.1EPSS 0.009
CVE-2021-3370
DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php.
Published 2021-12-08 · Modified
6.1EPSS 0.006
CVE-2022-25574
A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.
Published 2022-03-25 · Modified
4.8EPSS 0.004