Dotclear

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 32
    Known Exploited: 0
    2
    Critical Level Threats
    8
    High Level Threats
    20
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-53952

    Dotclear 2.25.3 Authenticated Remote Code Execution via File Upload

    Last Modified: Apr 07, 2026
    Published: Dec 19, 2025

    CVE-2024-58281

    Dotclear 2.29 Remote Code Execution via Authenticated File Upload

    Last Modified: Apr 07, 2026
    Published: Dec 10, 2025

    CVE-2024-27626

    A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.

    Last Modified: Jun 17, 2025
    Published: Mar 05, 2024

    CVE-2018-16358

    A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.

    Last Modified: Nov 21, 2024
    Published: Sep 02, 2018

    CVE-2018-5690

    Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the nb parameter (aka the page limit number).

    Last Modified: Nov 21, 2024
    Published: Jan 14, 2018
    Items Per Page
    Dotclear Vulnerabilities & Security CVEs | CVE-DB