Docebolms appears in the vulnerability landscape through a niche product bearing the same name; the observed disclosures lack sufficient specificity for reliable weakness-class characterization, reflected in the NVD placeholder classification. Treat this as a compact vendor profile where current severity, exploitation activity, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docebolms over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2668HIGH Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) modules/credits/bu | May 30, 2006 | 7.5 | 29 | NO | YES |
CVE-2005-4095MEDIUM Directory traversal vulnerability in connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to list arbitrary files and directories via ".." sequences | Dec 8, 2005 | 5.0 | 25 | NO | YES |
CVE-2005-4094HIGH connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to execute arbitrary PHP by using the FileUpload command to upload a file that appears to be an | Dec 8, 2005 | 7.5 | 20 | NO | NO |
CVE-2006-6857MEDIUM Cross-site scripting (XSS) vulnerability in modules/credits/credits.php in Docebo LMS allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | Dec 31, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docebolms.
Media articles that mention a CVE ID that affects a product developed by Docebolms — matched by CVE ID, not by vendor name.