Doorgets operates a narrowly scoped content-management and website-building platform that, despite limited product breadth, occupies a position among the more prominent vendors in the vulnerability landscape. Its disclosures concentrate around a cluster of foundational web-application security weaknesses: path traversal, SQL injection, missing authorization, cross-site request forgery, and insecure defaults—flaws endemic to the configuration and input-handling layers of CMS products. A meaningful share of its vulnerabilities reach serious severity, reflecting the exposure that arises when such weaknesses combine in a centrally managed platform serving multiple sites. Defenders relying on this vendor should prioritize security updates and apply defense-in-depth controls at the application and database tiers; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Doorgets over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11618CRITICAL doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification o | Apr 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11616CRITICAL doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php. A remote unauthenticated attacker could exploit this vulner | Apr 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11617HIGH doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modifica | Apr 30, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-11615HIGH /fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upload backdoor files to control t | Apr 30, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-11609HIGH doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-se | Apr 30, 2019 | 8.2 | 26 | NO | NO |
CVE-2019-11608HIGH doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server- | Apr 30, 2019 | 8.2 | 26 | NO | NO |
CVE-2018-11126HIGH dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account. | May 15, 2018 | 8.8 | 26 | NO | NO |
CVE-2014-1459MEDIUM SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_dow | Feb 11, 2014 | 6.5 | 26 | NO | YES |
CVE-2019-11610HIGH doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server | Apr 30, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-11606HIGH doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-se | Apr 30, 2019 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Doorgets.
Media articles that mention a CVE ID that affects a product developed by Doorgets — matched by CVE ID, not by vendor name.