Douphp
Vendor:
First CVE: Dec 24, 2018 · Active for 7 years
20
Total CVEs
More Total CVEs than 94% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Douphp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 24, 2018
7 years ago
Most Recent CVE
Feb 9, 2026
165 days ago
CVE Severity & Scoring
Douphp20 CVEs
80%
15%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (25.0%)
Unknown0 (0.0%)
Required15 (75.0%)
Privileges Required
Low1 (5.0%)
High13 (65.0%)
None6 (30.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12564CRITICAL In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames. | Jun 3, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-20419HIGH DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account. | Dec 24, 2018 | 8.8 | 26 | NO | NO |
CVE-2026-2226HIGH A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of t | Feb 9, 2026 | 7.2 | 23 | NO | NO |
CVE-2021-3370MEDIUM DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php. | Dec 8, 2021 | 6.1 | 22 | NO | NO |
CVE-2024-7917HIGH A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php | Aug 18, 2024 | 7.2 | 21 | NO | NO |
CVE-2022-25574MEDIUM A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file. | Mar 25, 2022 | 4.8 | 21 | NO | NO |
CVE-2018-20566MEDIUM An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page. | Dec 28, 2018 | 5.3 | 20 | NO | NO |
CVE-2022-46438MEDIUM A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows attackers to execute arbitrary web scripts or HTML via a craf | Jan 13, 2023 | 5.4 | 19 | NO | NO |
CVE-2018-20567MEDIUM An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which install.lock cannot be read. | Dec 28, 2018 | 5.3 | 19 | NO | NO |
CVE-2018-20565MEDIUM An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter. | Dec 28, 2018 | 4.8 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Douphp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.7_20231203 | 1 | 4.8 | 0.3% | 0 | 0 |
| 1.7_20221118 | 1 | 5.4 | 0.4% | 0 | 0 |
| 1.7 | 1 | 7.2 | 0.6% | 0 | 0 |
| 1.6 | 3 | 5.7 | 0.6% | 0 | 0 |
| 1.5 | 13 | 5.6 | 0.7% | 0 | 0 |