Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Domainmod

31 known vulnerabilities

2
CRITICAL
4
HIGH
25
MEDIUM

Top Products

domainmod 31
31 CVEs
5.3
CVE-2024-48624

In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a refl

5.3
CVE-2024-48623

In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited

6.6
CVE-2024-48622

A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admi

5.4
CVE-2020-20990

A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to exe

4.3
CVE-2020-20989

A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs

5.4
CVE-2020-20988

A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attacker

9.8
CVE-2020-35358

DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, bot

7.5
CVE-2019-9080

DomainMOD before 4.14.0 uses MD5 without a salt for password storage.

9.8
CVE-2020-12735

reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.

6.1
CVE-2019-15811

In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.

8.8
CVE-2019-1010096

DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that c

8.8
CVE-2019-1010095

DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that c

8.8
CVE-2019-1010094

domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that c

4.8
CVE-2018-1000856

DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) v

4.8
CVE-2018-20011

DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.

4.8
CVE-2018-20010

DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.

4.8
CVE-2018-20009

DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.

4.8
CVE-2018-19915

DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.

4.8
CVE-2018-19914

DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.

4.8
CVE-2018-19913

DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.

4.8
CVE-2018-19892

DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.

4.8
CVE-2018-19752

DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.

4.8
CVE-2018-19751

DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.

5.4
CVE-2018-19750

DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma

4.8
CVE-2018-19749

DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.

6.1
CVE-2018-19137

DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.

6.1
CVE-2018-19136

DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.

5.4
CVE-2018-11559

DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.

5.4
CVE-2018-11558

DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.

6.1
CVE-2018-11404

DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.

5.4
CVE-2018-11403

DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.

Frequently Asked Questions

How many CVEs affect Domainmod?

Domainmod has 31 CVE records in our database, including 2 critical and 4 high severity vulnerabilities.

What are the most severe Domainmod vulnerabilities?

Domainmod has 2 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Domainmod vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Domainmod products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Domainmod Vulnerabilities

CyberStrike scans your infrastructure for Domainmod vulnerabilities and provides real-time remediation guidance.

Get Started