Dotclear
32 known vulnerabilities
Top Products
Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious P
Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists withi
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1
Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inje
Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to injec
XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order paramete
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authen
Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to injec
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to m
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authentica
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remo
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear th
Frequently Asked Questions
How many CVEs affect Dotclear?
Dotclear has 32 CVE records in our database, including 0 critical and 10 high severity vulnerabilities.
What are the most severe Dotclear vulnerabilities?
Dotclear has 0 critical severity (CVSS 9.0+) and 10 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Dotclear vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Dotclear products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Dotclear Vulnerabilities
CyberStrike scans your infrastructure for Dotclear vulnerabilities and provides real-time remediation guidance.
Get Started