Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ddsn

First CVE: Jan 16, 2006Active for: 21 yearsTotal CVEs: 12
28.7
VTI Score
Low

Ddsn's vulnerability footprint centers on its CM3 Acora content management system, a web-based platform whose disclosures cluster around application-layer access and input-handling weaknesses. The recurring exposure reflects the authentication and data-protection demands of CMS software, spanning improper access control, CSRF, cross-site scripting, improper input validation, and exposure of sensitive information to unauthorized actors. A meaningful share of vulnerabilities reach serious severity, and the profile carries a moderate tendency toward public exploit availability; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ddsn over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2006
20 years ago
Most Recent CVE
Jan 12, 2026
193 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-63314CRITICAL
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full accoun
Jan 12, 202610.037NONO
CVE-2025-25967HIGH
Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as
Mar 3, 20258.823NONO
CVE-2013-4727MEDIUM
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Adm
Jun 6, 20145.023NOYES
CVE-2025-22964HIGH
DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "t
Jan 15, 20258.122NONO
CVE-2025-25968MEDIUM
DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administ
Feb 20, 20256.020NONO
CVE-2006-0221HIGH
SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL c
Jan 16, 20067.519NONO
CVE-2013-4726MEDIUM
Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers t
Apr 25, 20146.818NONO
CVE-2013-4723MEDIUM
Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows remote attackers to redirect users to a
Apr 25, 20145.817NONO
CVE-2013-4728MEDIUM
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a .. (dot dot) i
Jun 6, 20145.015NONO
CVE-2013-4725MEDIUM
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session,
Jun 6, 20145.015NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
67%
25%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (33.3%)
Unknown8 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (33.3%)
High0 (0.0%)
Unknown8 (66.7%)
User Interaction
None3 (25.0%)
Unknown8 (66.7%)
Required1 (8.3%)
Privileges Required
Low1 (8.3%)
High1 (8.3%)
None2 (16.7%)
Unknown8 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ddsn.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ddsn — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ddsn's Products

View all 1 CNAs →

Top CWEs