Ddsn's vulnerability footprint centers on its CM3 Acora content management system, a web-based platform whose disclosures cluster around application-layer access and input-handling weaknesses. The recurring exposure reflects the authentication and data-protection demands of CMS software, spanning improper access control, CSRF, cross-site scripting, improper input validation, and exposure of sensitive information to unauthorized actors. A meaningful share of vulnerabilities reach serious severity, and the profile carries a moderate tendency toward public exploit availability; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ddsn over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63314CRITICAL A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full accoun | Jan 12, 2026 | 10.0 | 37 | NO | NO |
CVE-2025-25967HIGH Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as | Mar 3, 2025 | 8.8 | 23 | NO | NO |
CVE-2013-4727MEDIUM DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Adm | Jun 6, 2014 | 5.0 | 23 | NO | YES |
CVE-2025-22964HIGH DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "t | Jan 15, 2025 | 8.1 | 22 | NO | NO |
CVE-2025-25968MEDIUM DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administ | Feb 20, 2025 | 6.0 | 20 | NO | NO |
CVE-2006-0221HIGH SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL c | Jan 16, 2006 | 7.5 | 19 | NO | NO |
CVE-2013-4726MEDIUM Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers t | Apr 25, 2014 | 6.8 | 18 | NO | NO |
CVE-2013-4723MEDIUM Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows remote attackers to redirect users to a | Apr 25, 2014 | 5.8 | 17 | NO | NO |
CVE-2013-4728MEDIUM DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a .. (dot dot) i | Jun 6, 2014 | 5.0 | 15 | NO | NO |
CVE-2013-4725MEDIUM DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, | Jun 6, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ddsn.
Media articles that mention a CVE ID that affects a product developed by Ddsn — matched by CVE ID, not by vendor name.