Docebo maintains a learning-management platform with a focused product footprint but sits prominently in the educational and corporate training landscape. Its vulnerability profile centers on application-layer input-handling and code-generation weaknesses—SQL injection, cross-site scripting, code injection, and sensitive-information exposure—that recur across its platform, and these disclosures frequently acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docebo over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31362HIGH Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer suppor | Jun 23, 2022 | 8.8 | 36 | NO | NO |
CVE-2022-31361CRITICAL Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by th | Jun 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2009-4742HIGH Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter in a play help action to the faq module | Mar 26, 2010 | 7.5 | 29 | NO | YES |
CVE-2011-5135MEDIUM Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and earlier allow remote authenticated users wi | Aug 30, 2012 | 6.0 | 28 | NO | YES |
CVE-2008-7153HIGH SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL command | Sep 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2006-2576MEDIUM Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in | May 24, 2006 | 5.1 | 26 | NO | YES |
CVE-2007-1240MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter | Mar 3, 2007 | 4.3 | 24 | NO | YES |
CVE-2008-7154MEDIUM Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.module/class.event_manager.php, (3 | Sep 2, 2009 | 5.0 | 23 | NO | YES |
CVE-2006-2577MEDIUM Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in | May 24, 2006 | 5.1 | 23 | NO | YES |
CVE-2006-6963HIGH Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 3.0.3 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_lms] parameter to (1) cla | Jan 29, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docebo.
Media articles that mention a CVE ID that affects a product developed by Docebo — matched by CVE ID, not by vendor name.