Doorgets Cms
Vendor:
First CVE: Feb 11, 2014 · Active for 12 years
22
Total CVEs
More Total CVEs than 94% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Doorgets Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2014
12 years ago
Most Recent CVE
Apr 30, 2019
2,642 days ago
CVE Severity & Scoring
Doorgets Cms22 CVEs
45%
45%
9%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (95.5%)
Unknown1 (4.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High0 (0.0%)
Unknown1 (4.5%)
User Interaction
None20 (90.9%)
Unknown1 (4.5%)
Required1 (4.5%)
Privileges Required
Low2 (9.1%)
High7 (31.8%)
None12 (54.5%)
Unknown1 (4.5%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11618CRITICAL doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification o | Apr 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11616CRITICAL doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php. A remote unauthenticated attacker could exploit this vulner | Apr 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11617HIGH doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modifica | Apr 30, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-11615HIGH /fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upload backdoor files to control t | Apr 30, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-11609HIGH doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-se | Apr 30, 2019 | 8.2 | 26 | NO | NO |
CVE-2019-11608HIGH doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server- | Apr 30, 2019 | 8.2 | 26 | NO | NO |
CVE-2014-1459MEDIUM SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_dow | Feb 11, 2014 | 6.5 | 26 | NO | YES |
CVE-2019-11610HIGH doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server | Apr 30, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-11606HIGH doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-se | Apr 30, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-11612HIGH doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php. A remote unauthenticated attacker can exploit this vulnerability to delete arbitrary files | Apr 30, 2019 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.5% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Doorgets Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 21 | 6.9 | 2.2% | 0 | 0 |
| 4.0 | 1 | 6.5 | 2.3% | 0 | 1 |
| 3.0 | 1 | 6.5 | 2.3% | 0 | 1 |