Dotonpaper's vulnerability profile centers on a small set of web-based plugins and tools, namely its booking system and shortcode components, with the observed weakness classes focused on application-layer input handling: cross-site scripting and SQL injection. These patterns are typical of web-facing PHP or WordPress ecosystem products where unsanitized user input flows into page generation and database queries; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dotonpaper over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3210MEDIUM SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitra | May 22, 2014 | 6.5 | 27 | NO | YES |
CVE-2024-4377MEDIUM The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embe | Jun 21, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dotonpaper.
Media articles that mention a CVE ID that affects a product developed by Dotonpaper — matched by CVE ID, not by vendor name.