Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Docsys Project

First CVE: Dec 11, 2022Active for: 4 yearsTotal CVEs: 8

Docsys Project maintains a narrowly focused documentation and content-management system whose vulnerability profile is characterized by input-handling and access-control weaknesses across path traversal, injection, and SQL-injection classes that recur in web-facing document-handling and database-integration layers. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, reflecting the high-impact nature of injection flaws in systems that process and serve user-controlled content. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Docsys Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2022
3 years ago
Most Recent CVE
Jan 9, 2026
197 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-11629CRITICAL
A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection.
Oct 12, 20259.833NONO
CVE-2025-11630CRITICAL
A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing manipulati
Oct 12, 20259.830NONO
CVE-2025-15493CRITICAL
A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMapper.xml. Executing a manipulat
Jan 9, 20269.829NONO
CVE-2025-15494HIGH
A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSystem/mapping/UserMapper.xml. The manipulation of the argument
Jan 9, 20268.827NONO
CVE-2025-15492HIGH
A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file src/com/DocSystem/mapping/GroupMemberMapper.xml. Performing a
Jan 9, 20268.827NONO
CVE-2025-11631CRITICAL
A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do. Executing manipulation of
Oct 12, 20259.127NONO
CVE-2022-4511HIGH
A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unknown functionality of the component com.DocSystem.controller.U
Dec 15, 20227.524NONO
CVE-2022-4402HIGH
A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation lea
Dec 11, 20227.224NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
50%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (25.0%)
High1 (12.5%)
None5 (62.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Docsys Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Docsys Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Docsys Project's Products

View all 1 CNAs →

Top CWEs