Domainmod is a domain and DNS management platform with a modestly represented vulnerability footprint concentrated entirely within its single self-hosted application. A meaningful share of its disclosures reach serious severity, and the vendor's vulnerabilities frequently acquire public exploit code, reflecting both the accessibility of its open-source codebase and the attractiveness of domain-management infrastructure as a target. The recurring weakness classes center on web-application input handling and session management—including cross-site scripting, cross-site request forgery, insufficient session expiration, and weak password hashing—that are characteristic of authentication and administrative interfaces. Defenders operating this platform should prioritize tracking upstream updates and isolating administrative access; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Domainmod over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15811MEDIUM In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS. | Aug 29, 2019 | 6.1 | 42 | NO | YES |
CVE-2018-19136MEDIUM DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter. | Nov 9, 2018 | 6.1 | 42 | NO | YES |
CVE-2018-20011MEDIUM DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. | Dec 10, 2018 | 4.8 | 36 | NO | YES |
CVE-2018-20010MEDIUM DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field. | Dec 10, 2018 | 4.8 | 36 | NO | YES |
CVE-2018-20009MEDIUM DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field. | Dec 10, 2018 | 4.8 | 36 | NO | YES |
CVE-2018-19915MEDIUM DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field. | Dec 6, 2018 | 4.8 | 36 | NO | YES |
CVE-2018-19752MEDIUM DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar. | Nov 29, 2018 | 4.8 | 36 | NO | YES |
CVE-2018-19751MEDIUM DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields. | Nov 29, 2018 | 4.8 | 36 | NO | YES |
CVE-2018-19914MEDIUM DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field. | Dec 6, 2018 | 4.8 | 35 | NO | YES |
CVE-2018-19749MEDIUM DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field. | Nov 29, 2018 | 4.8 | 35 | NO | YES |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Domainmod.
Media articles that mention a CVE ID that affects a product developed by Domainmod — matched by CVE ID, not by vendor name.