Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dot Project

First CVE: Apr 11, 2003Active for: 23 yearsTotal CVEs: 17

Dot Project is a narrowly scoped project-management application whose vulnerability profile centers on server-side code-injection and prototype-pollution weaknesses affecting its web application layer. These weakness classes reflect risks inherent to dynamic code handling and object manipulation in web frameworks, and current severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 56% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dot Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2003
23 years ago
Most Recent CVE
Apr 6, 2020
2,300 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2002-1428HIGH
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.
Apr 11, 200310.043NOYES
CVE-2012-5701MEDIUM
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where
Oct 20, 20146.831NOYES
CVE-2006-4234HIGH
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir pa
Aug 18, 20067.530NOYES
CVE-2006-0755MEDIUM
Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the bas
Feb 18, 20065.627NOYES
CVE-2012-5702MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a col
Oct 21, 20144.325NOYES
CVE-2020-8141HIGH
The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Ob
Mar 15, 20208.822NONO
CVE-2020-7639MEDIUM
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto_
Apr 6, 20205.319NONO
CVE-2011-3729MEDIUM
dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrat
Sep 23, 20115.018NONO
CVE-2008-6747MEDIUM
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from
Apr 23, 20096.818NONO
CVE-2008-3887MEDIUM
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects a
Sep 2, 20086.018NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
82%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (17.6%)
Unknown14 (82.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (11.8%)
High1 (5.9%)
Unknown14 (82.4%)
User Interaction
None3 (17.6%)
Unknown14 (82.4%)
Required0 (0.0%)
Privileges Required
Low1 (5.9%)
High0 (0.0%)
None2 (11.8%)
Unknown14 (82.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
29.4% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dot Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dot Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dot Project's Products

View all 3 CNAs →

Top CWEs