Dovestones

    Dashboard / Vendors

    Products: 4
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-36460

    Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding.

    Last Modified: Jun 08, 2026
    Published: Jun 03, 2026

    CVE-2026-31013

    Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in the victim's browser.

    Last Modified: Apr 23, 2026
    Published: Apr 21, 2026

    CVE-2026-31014

    Cross‑Site Request Forgery Enables Unauthorized User Account Modification

    Last Modified: Apr 23, 2026
    Published: Apr 21, 2026

    CVE-2015-8267

    The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username.

    Last Modified: Apr 12, 2025
    Published: Dec 24, 2015
    Items Per Page