Docsys Project maintains a narrowly focused documentation and content-management system whose vulnerability profile is characterized by input-handling and access-control weaknesses across path traversal, injection, and SQL-injection classes that recur in web-facing document-handling and database-integration layers. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, reflecting the high-impact nature of injection flaws in systems that process and serve user-controlled content. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docsys Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11629CRITICAL A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection. | Oct 12, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-11630CRITICAL A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing manipulati | Oct 12, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-15493CRITICAL A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMapper.xml. Executing a manipulat | Jan 9, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-15494HIGH A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSystem/mapping/UserMapper.xml. The manipulation of the argument | Jan 9, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-15492HIGH A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file src/com/DocSystem/mapping/GroupMemberMapper.xml. Performing a | Jan 9, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-11631CRITICAL A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do. Executing manipulation of | Oct 12, 2025 | 9.1 | 27 | NO | NO |
CVE-2022-4511HIGH A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unknown functionality of the component com.DocSystem.controller.U | Dec 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-4402HIGH A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation lea | Dec 11, 2022 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docsys Project.
Media articles that mention a CVE ID that affects a product developed by Docsys Project — matched by CVE ID, not by vendor name.