Dotproject is a modestly represented project-management and collaboration platform whose vulnerability profile centers on web-application input-handling and access-control issues. The recurring weakness classes—including cross-site scripting, SQL injection, cross-site request forgery, and sensitive information exposure—are characteristic of web applications where input validation and session-handling maturity varies, and the vendor's disclosures have frequently acquired public exploit code. Defenders should prioritize patches for this product where it is internet-exposed or handles sensitive project data; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dotproject over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1428HIGH index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1. | Apr 11, 2003 | 10.0 | 43 | NO | YES |
CVE-2012-5701MEDIUM Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where | Oct 20, 2014 | 6.8 | 31 | NO | YES |
CVE-2006-4234HIGH PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir pa | Aug 18, 2006 | 7.5 | 30 | NO | YES |
CVE-2006-0755MEDIUM Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the bas | Feb 18, 2006 | 5.6 | 27 | NO | YES |
CVE-2012-5702MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a col | Oct 21, 2014 | 4.3 | 25 | NO | YES |
CVE-2020-8141HIGH The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Ob | Mar 15, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-7639MEDIUM eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto_ | Apr 6, 2020 | 5.3 | 19 | NO | NO |
CVE-2011-3729MEDIUM dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrat | Sep 23, 2011 | 5.0 | 18 | NO | NO |
CVE-2008-6747MEDIUM dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from | Apr 23, 2009 | 6.8 | 18 | NO | NO |
CVE-2008-3887MEDIUM Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects a | Sep 2, 2008 | 6.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dotproject.
Media articles that mention a CVE ID that affects a product developed by Dotproject — matched by CVE ID, not by vendor name.