dotCMS LLC maintains a content management system widely deployed in enterprise publishing and digital-experience platforms, where its vulnerability profile concentrates on a single product spanning a moderate volume of disclosures. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency to acquire public exploit code. The exposure recurs through classic web-application weakness classes including cross-site scripting, SQL injection, path traversal, and unrestricted file uploads, reflecting the input-handling and file-processing demands inherent to a content-management platform. Defenders should prioritize this vendor's security updates for internet-facing instances and apply strict input validation and file-upload controls; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by dotCMS LLC over time
Of all the CVEs published by dotCMS LLC as a CNA, 66.7% affect products that dotCMS LLC develops as a vendor.
Of all the CVEs published that affect products developed by dotCMS LLC, 10.3% are self-published by dotCMS LLC as a CNA.
Signals from CVEs in this vendor scope (58 CVEs).
58 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26352CRITICAL An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitize | Jul 17, 2022 | 9.8 | 98 | YES | YES |
CVE-2020-6754CRITICAL dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets | Feb 5, 2020 | 9.8 | 75 | NO | NO |
CVE-2017-5344CRITICAL An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and | Feb 17, 2017 | 9.8 | 44 | NO | YES |
CVE-2026-16337CRITICAL Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated ba | Jul 20, 2026 | 9.4 | 37 | NO | NO |
CVE-2018-17422MEDIUM dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter. | Mar 7, 2019 | 6.1 | 32 | NO | YES |
CVE-2016-2355CRITICAL SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1. | Dec 19, 2016 | 9.8 | 32 | NO | NO |
CVE-2016-8902CRITICAL SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort paramet | Nov 14, 2016 | 9.8 | 31 | NO | NO |
CVE-2025-11165CRITICAL A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restricti | Feb 24, 2026 | 9.9 | 30 | NO | NO |
CVE-2022-45782HIGH An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generat | Feb 1, 2023 | 8.8 | 28 | NO | NO |
CVE-2016-8907HIGH SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the ord | Nov 14, 2016 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (58 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by dotCMS LLC.
Media articles that mention a CVE ID that affects a product developed by dotCMS LLC — matched by CVE ID, not by vendor name.