Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Docebo

First CVE: May 24, 2006Active for: 20 yearsTotal CVEs: 13
40.8
VTI Score
High

Docebo maintains a learning-management platform with a focused product footprint but sits prominently in the educational and corporate training landscape. Its vulnerability profile centers on application-layer input-handling and code-generation weaknesses—SQL injection, cross-site scripting, code injection, and sensitive-information exposure—that recur across its platform, and these disclosures frequently acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Docebo over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2006
20 years ago
Most Recent CVE
Jun 23, 2022
1,492 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-31362HIGH
Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer suppor
Jun 23, 20228.836NONO
CVE-2022-31361CRITICAL
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by th
Jun 23, 20229.830NONO
CVE-2009-4742HIGH
Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter in a play help action to the faq module
Mar 26, 20107.529NOYES
CVE-2011-5135MEDIUM
Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and earlier allow remote authenticated users wi
Aug 30, 20126.028NOYES
CVE-2008-7153HIGH
SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL command
Sep 2, 20097.528NOYES
CVE-2006-2576MEDIUM
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in
May 24, 20065.126NOYES
CVE-2007-1240MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter
Mar 3, 20074.324NOYES
CVE-2008-7154MEDIUM
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.module/class.event_manager.php, (3
Sep 2, 20095.023NOYES
CVE-2006-2577MEDIUM
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in
May 24, 20065.123NOYES
CVE-2006-6963HIGH
Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 3.0.3 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_lms] parameter to (1) cla
Jan 29, 20077.519NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
62%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (15.4%)
Unknown11 (84.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (15.4%)
High0 (0.0%)
Unknown11 (84.6%)
User Interaction
None2 (15.4%)
Unknown11 (84.6%)
Required0 (0.0%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None1 (7.7%)
Unknown11 (84.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
53.8% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Docebo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Docebo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Docebo's Products

View all 1 CNAs →

Top CWEs