Docman is a narrowly scoped document-management product with a modest vulnerability footprint centered on the core application itself. The limited disclosure record reflects generalized weakness classifications rather than a clear pattern of specific flaw types, making structural analysis difficult at this volume. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docman over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0378HIGH Multiple SQL injection vulnerabilities in DocMan 1.3 RC2 allow attackers to execute arbitrary SQL commands via unspecified vectors. | Jan 19, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-0379MEDIUM Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jan 19, 2007 | 6.8 | 18 | NO | NO |
CVE-2007-0380MEDIUM DocMan 1.3 RC2 allows remote attackers to obtain sensitive information (the full path) via unspecified vectors. | Jan 19, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docman.
Media articles that mention a CVE ID that affects a product developed by Docman — matched by CVE ID, not by vendor name.