Vendorshtml-jsdoracmsany version
Vulnerabilities

html-js DoraCMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-35147
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
Published 2022-08-17 · Modified
9.8EPSS 0.015
CVE-2026-3794
doramart DoraCMS Email API send improper authentication
Published 2026-03-09 · Analyzed
9.8EPSS 0.010
CVE-2026-3795
doramart DoraCMS v1.js createFileBypath path traversal
Published 2026-03-09 · Analyzed
9.8EPSS 0.008
CVE-2024-28715
Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.
Published 2024-03-19 · Analyzed
8.8EPSS 0.011
CVE-2020-18220
Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.
Published 2021-05-20 · Modified
7.5EPSS 0.004