dotCMS LLC
First CVE: Oct 17, 2023Active for: 3 years
9
CVEs Published
More CVEs Published than 25% of tracked CNAs
2.3
Avg CVEs / Year
More Avg CVEs / Year than 15% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 79% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by dotCMS LLC as a CNA, 66.7% affect products that dotCMS LLC develops as a vendor.
66.7%
33.3%
Self-reported: 6Third-party: 3
Of all the CVEs published that affect products developed by dotCMS LLC, 10.3% are self-published by dotCMS LLC as a CNA.
10.3%
89.7%
Self-published: 6Published by other CNAs: 52
Trends Over Time
The number and severity of CVEs published by dotCMS LLC over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 17, 2023
2 years ago
Most Recent CVE
Jul 20, 2026
4 days ago
Top CVEs
All CVEs published by dotCMS LLC as a CNA, regardless of affected vendor or product.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8054CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) i | May 27, 2026 | 10.0 | 51 | NO | YES |
CVE-2025-8311CRITICAL dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint. This endpoint uses the sites query parameter, which acc | Sep 4, 2025 | 9.4 | 39 | NO | YES |
CVE-2026-16337CRITICAL Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated ba | Jul 20, 2026 | 9.4 | 37 | NO | NO |
CVE-2024-4447CRITICAL In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dwr) calls. While this | Jul 26, 2024 | 9.9 | 32 | NO | NO |
CVE-2025-11165CRITICAL A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restricti | Feb 24, 2026 | 9.9 | 30 | NO | NO |
CVE-2024-3938MEDIUM The "reset password" login page accepted an HTML injection via URL parameters.
This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. | Jul 25, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-3042MEDIUM In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS and access controls. An example | Oct 17, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-3165MEDIUM System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requ | Apr 1, 2024 | 4.5 | 16 | NO | NO |
CVE-2024-3164MEDIUM In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and n | Apr 1, 2024 | 4.5 | 14 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA9 CVEs
44%
56%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low3 (33.3%)
High3 (33.3%)
None3 (33.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 97th percentile
ExploitDB
1 CVE
11.1% of CVEs· 98th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by dotCMS LLC as a CNA.
Media Mentions
Media articles that mention a CVE ID published by dotCMS LLC as a CNA — matched by CVE ID, not by organization name.