Dotclear is a self-hosted blogging and content-management platform whose vulnerability footprint, while concentrated in a single product, sits at the intersection of web-application input handling and file-upload workflows. The vendor's disclosures recur consistently through application-layer weakness classes including cross-site scripting, code injection, unsafe file uploads, and improper access control—flaws typical of content-management systems where user input, template rendering, and privilege boundaries are core attack surfaces. Notably, vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting both the open-source nature of the platform and the accessibility of its deployment model. Defenders should treat updates to this vendor's core product as a patching priority for any instances exposed to untrusted content contribution or network access; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dotclear over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-53952HIGH Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension through the blog post creation | Dec 19, 2025 | 8.8 | 29 | NO | NO |
CVE-2015-8832HIGH Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "manag | Feb 9, 2017 | 8.8 | 29 | NO | NO |
CVE-2016-7902HIGH Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute | Jan 4, 2017 | 8.8 | 29 | NO | NO |
CVE-2024-58281HIGH Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can | Dec 10, 2025 | 8.8 | 28 | NO | NO |
CVE-2005-3963HIGH SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie. | Dec 2, 2005 | 7.5 | 28 | NO | YES |
CVE-2012-1039MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin | Mar 19, 2012 | 4.3 | 26 | NO | YES |
CVE-2005-3957HIGH Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors. | Dec 1, 2005 | 10.0 | 25 | NO | NO |
CVE-2014-1613HIGH Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly hand | May 16, 2014 | 7.5 | 24 | NO | NO |
CVE-2011-5083HIGH Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable | Mar 19, 2012 | 7.5 | 24 | NO | NO |
CVE-2008-3232HIGH Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an | Jul 18, 2008 | 9.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dotclear.
Media articles that mention a CVE ID that affects a product developed by Dotclear — matched by CVE ID, not by vendor name.