Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Domainmod

First CVE: May 24, 2018Active for: 8 yearsTotal CVEs: 31
32.5
VTI Score
Medium

Domainmod is a domain and DNS management platform with a modestly represented vulnerability footprint concentrated entirely within its single self-hosted application. A meaningful share of its disclosures reach serious severity, and the vendor's vulnerabilities frequently acquire public exploit code, reflecting both the accessibility of its open-source codebase and the attractiveness of domain-management infrastructure as a target. The recurring weakness classes center on web-application input handling and session management—including cross-site scripting, cross-site request forgery, insufficient session expiration, and weak password hashing—that are characteristic of authentication and administrative interfaces. Defenders operating this platform should prioritize tracking upstream updates and isolating administrative access; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
6.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Domainmod over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2018
8 years ago
Most Recent CVE
Oct 15, 2024
647 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-15811MEDIUM
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
Aug 29, 20196.142NOYES
CVE-2018-19136MEDIUM
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
Nov 9, 20186.142NOYES
CVE-2018-20011MEDIUM
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
Dec 10, 20184.836NOYES
CVE-2018-20010MEDIUM
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
Dec 10, 20184.836NOYES
CVE-2018-20009MEDIUM
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
Dec 10, 20184.836NOYES
CVE-2018-19915MEDIUM
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
Dec 6, 20184.836NOYES
CVE-2018-19752MEDIUM
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
Nov 29, 20184.836NOYES
CVE-2018-19751MEDIUM
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
Nov 29, 20184.836NOYES
CVE-2018-19914MEDIUM
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.
Dec 6, 20184.835NOYES
CVE-2018-19749MEDIUM
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
Nov 29, 20184.835NOYES
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
81%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (9.7%)
Network28 (90.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (19.4%)
Unknown0 (0.0%)
Required25 (80.6%)
Privileges Required
Low9 (29.0%)
High11 (35.5%)
None11 (35.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
14 CVEs
45.2% of CVEs· 98th percentile
ExploitDB
14 CVEs
45.2% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Domainmod.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Domainmod — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Domainmod's Products

View all 2 CNAs →

Top CWEs