Douco maintains DouPHP, a web application framework that occupies a notable niche in its deployment context despite a narrow product footprint. The vendor's vulnerability exposure centers on application-layer weaknesses inherent to web frameworks: cross-site scripting, unrestricted file uploads, cross-site request forgery, improper access control, and authentication flaws recur across its disclosures. These weakness classes reflect the complexity of input handling, session management, and file-handling logic in web application platforms, and are patterns that defenders should monitor closely in any framework that processes untrusted user input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Douco over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12564CRITICAL In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames. | Jun 3, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-20419HIGH DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account. | Dec 24, 2018 | 8.8 | 26 | NO | NO |
CVE-2026-2226HIGH A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of t | Feb 9, 2026 | 7.2 | 23 | NO | NO |
CVE-2021-3370MEDIUM DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php. | Dec 8, 2021 | 6.1 | 22 | NO | NO |
CVE-2024-7917HIGH A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php | Aug 18, 2024 | 7.2 | 21 | NO | NO |
CVE-2022-25574MEDIUM A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file. | Mar 25, 2022 | 4.8 | 21 | NO | NO |
CVE-2018-20566MEDIUM An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page. | Dec 28, 2018 | 5.3 | 20 | NO | NO |
CVE-2022-46438MEDIUM A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows attackers to execute arbitrary web scripts or HTML via a craf | Jan 13, 2023 | 5.4 | 19 | NO | NO |
CVE-2018-20567MEDIUM An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which install.lock cannot be read. | Dec 28, 2018 | 5.3 | 19 | NO | NO |
CVE-2018-20565MEDIUM An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter. | Dec 28, 2018 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Douco.
Media articles that mention a CVE ID that affects a product developed by Douco — matched by CVE ID, not by vendor name.