Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Doorgets

First CVE: Feb 11, 2014Active for: 12 yearsTotal CVEs: 24
47.4
VTI Score
High

Doorgets operates a narrowly scoped content-management and website-building platform that, despite limited product breadth, occupies a position among the more prominent vendors in the vulnerability landscape. Its disclosures concentrate around a cluster of foundational web-application security weaknesses: path traversal, SQL injection, missing authorization, cross-site request forgery, and insecure defaults—flaws endemic to the configuration and input-handling layers of CMS products. A meaningful share of its vulnerabilities reach serious severity, reflecting the exposure that arises when such weaknesses combine in a centrally managed platform serving multiple sites. Defenders relying on this vendor should prioritize security updates and apply defense-in-depth controls at the application and database tiers; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Doorgets over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2014
12 years ago
Most Recent CVE
Apr 30, 2019
2,642 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11618CRITICAL
doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification o
Apr 30, 20199.829NONO
CVE-2019-11616CRITICAL
doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php. A remote unauthenticated attacker could exploit this vulner
Apr 30, 20199.829NONO
CVE-2019-11617HIGH
doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modifica
Apr 30, 20198.826NONO
CVE-2019-11615HIGH
/fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upload backdoor files to control t
Apr 30, 20198.826NONO
CVE-2019-11609HIGH
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-se
Apr 30, 20198.226NONO
CVE-2019-11608HIGH
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-
Apr 30, 20198.226NONO
CVE-2018-11126HIGH
dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account.
May 15, 20188.826NONO
CVE-2014-1459MEDIUM
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_dow
Feb 11, 20146.526NOYES
CVE-2019-11610HIGH
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server
Apr 30, 20197.525NONO
CVE-2019-11606HIGH
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-se
Apr 30, 20197.525NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
42%
50%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (95.8%)
Unknown1 (4.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High0 (0.0%)
Unknown1 (4.2%)
User Interaction
None21 (87.5%)
Unknown1 (4.2%)
Required2 (8.3%)
Privileges Required
Low2 (8.3%)
High7 (29.2%)
None14 (58.3%)
Unknown1 (4.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Doorgets.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Doorgets — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Doorgets's Products

View all 1 CNAs →

Top CWEs