Docmosis is a document-generation platform centered on its Tornado product, which converts templates into formatted output across enterprise workflows. The recurring vulnerability signals cluster around authentication bypasses, code-injection conditions, and path-traversal flaws that reflect the risks inherent in template processing and dynamic file handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docmosis over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25266HIGH An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office directory setting pointing to an arbitrary remote network path. | Feb 28, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-42733CRITICAL An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script to the UNC path input | Mar 7, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-25265HIGH Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the file system. | Feb 28, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-25264HIGH An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially cra | Feb 28, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docmosis.
Media articles that mention a CVE ID that affects a product developed by Docmosis — matched by CVE ID, not by vendor name.