ddsn CVE Vulnerabilities & Metrics

Focus on ddsn vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About ddsn Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with ddsn. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total ddsn CVEs: 1
Earliest CVE date: 16 Jan 2006, 21:03 UTC
Latest CVE date: 03 Mar 2025, 19:15 UTC

Latest CVE reference: CVE-2025-25967

Rolling Stats

30-day Count (Rolling): 1
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical ddsn CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.93

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 7
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS ddsn CVEs

These are the five CVEs with the highest CVSS scores for ddsn, sorted by severity first and recency.

All CVEs for ddsn

CVE-2025-25967 ddsn vulnerability CVSS: 0 03 Mar 2025, 19:15 UTC

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.

CVE-2013-4728 ddsn vulnerability CVSS: 5.0 06 Jun 2014, 14:55 UTC

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a .. (dot dot) in the "l" parameter, which reveals the installation path in an error message.

CVE-2013-4727 ddsn vulnerability CVSS: 5.0 06 Jun 2014, 14:55 UTC

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Admin/top.aspx.

CVE-2013-4725 ddsn vulnerability CVSS: 5.0 06 Jun 2014, 14:55 UTC

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVE-2013-4724 ddsn vulnerability CVSS: 5.0 06 Jun 2014, 14:55 UTC

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2013-4726 ddsn vulnerability CVSS: 6.8 25 Apr 2014, 17:12 UTC

Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2013-4723 ddsn vulnerability CVSS: 5.8 25 Apr 2014, 17:12 UTC

Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the l parameter to track.aspx.

CVE-2013-4722 ddsn vulnerability CVSS: 4.3 25 Apr 2014, 17:12 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) url, (3) qstr parameter.

CVE-2006-0221 ddsn vulnerability CVSS: 7.5 16 Jan 2006, 21:03 UTC

SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.