Doorgets Cms

Vendor:

First CVE: Feb 11, 2014 · Active for 12 years

22
Total CVEs
More Total CVEs than 94% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Doorgets Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2014
12 years ago
Most Recent CVE
Apr 30, 2019
2,642 days ago

CVE Severity & Scoring

Doorgets Cms22 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (95.5%)
Unknown1 (4.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High0 (0.0%)
Unknown1 (4.5%)
User Interaction
None20 (90.9%)
Unknown1 (4.5%)
Required1 (4.5%)
Privileges Required
Low2 (9.1%)
High7 (31.8%)
None12 (54.5%)
Unknown1 (4.5%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification o
Apr 30, 20199.829NONO
doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php. A remote unauthenticated attacker could exploit this vulner
Apr 30, 20199.829NONO
doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modifica
Apr 30, 20198.826NONO
/fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upload backdoor files to control t
Apr 30, 20198.826NONO
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-se
Apr 30, 20198.226NONO
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-
Apr 30, 20198.226NONO
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_dow
Feb 11, 20146.526NOYES
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server
Apr 30, 20197.525NONO
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-se
Apr 30, 20197.525NONO
doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php. A remote unauthenticated attacker can exploit this vulnerability to delete arbitrary files
Apr 30, 20197.524NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.5% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Doorgets Cms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0216.92.2%00
4.016.52.3%01
3.016.52.3%01