domainmod CVE Vulnerabilities & Metrics

Focus on domainmod vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About domainmod Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with domainmod. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total domainmod CVEs: 28
Earliest CVE date: 24 May 2018, 07:29 UTC
Latest CVE date: 12 Aug 2021, 22:15 UTC

Latest CVE reference: CVE-2020-20990

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical domainmod CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.34

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 17
4.0-6.9 9
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS domainmod CVEs

These are the five CVEs with the highest CVSS scores for domainmod, sorted by severity first and recency.

All CVEs for domainmod

CVE-2020-20990 domainmod vulnerability CVSS: 3.5 12 Aug 2021, 22:15 UTC

A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter.

CVE-2020-20989 domainmod vulnerability CVSS: 4.3 12 Aug 2021, 22:15 UTC

A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs.

CVE-2020-20988 domainmod vulnerability CVSS: 3.5 12 Aug 2021, 22:15 UTC

A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parameter.

CVE-2020-35358 domainmod vulnerability CVSS: 7.5 15 Mar 2021, 12:15 UTC

DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.

CVE-2019-9080 domainmod vulnerability CVSS: 5.0 20 Oct 2020, 20:15 UTC

DomainMOD before 4.14.0 uses MD5 without a salt for password storage.

CVE-2020-12735 domainmod vulnerability CVSS: 7.5 08 May 2020, 05:15 UTC

reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.

CVE-2019-15811 domainmod vulnerability CVSS: 4.3 29 Aug 2019, 19:15 UTC

In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.

CVE-2019-1010096 domainmod vulnerability CVSS: 6.8 18 Jul 2019, 13:15 UTC

DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user to admin. The component is: admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html page.

CVE-2019-1010095 domainmod vulnerability CVSS: 6.8 18 Jul 2019, 13:15 UTC

DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator account. The component is: admin/users/add.php. The attack vector is: After the administrator logged in, open the html page.

CVE-2019-1010094 domainmod vulnerability CVSS: 6.8 18 Jul 2019, 13:15 UTC

domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The component is: http://127.0.0.1/settings/password/ http://127.0.0.1/admin/users/add.php http://127.0.0.1/admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html page.

CVE-2018-1000856 domainmod vulnerability CVSS: 3.5 20 Dec 2018, 17:29 UTC

DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) vulnerability in Segment Name field in the segments page that can result in Arbitrary script can be executed on all users browsers who visit the affected page. This attack appear to be exploitable via Victim must visit the vulnerable page. This vulnerability appears to have been fixed in No fix yet.

CVE-2018-20011 domainmod vulnerability CVSS: 3.5 10 Dec 2018, 09:29 UTC

DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.

CVE-2018-20010 domainmod vulnerability CVSS: 3.5 10 Dec 2018, 09:29 UTC

DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.

CVE-2018-20009 domainmod vulnerability CVSS: 3.5 10 Dec 2018, 09:29 UTC

DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.

CVE-2018-19915 domainmod vulnerability CVSS: 3.5 06 Dec 2018, 19:29 UTC

DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.

CVE-2018-19914 domainmod vulnerability CVSS: 3.5 06 Dec 2018, 19:29 UTC

DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.

CVE-2018-19913 domainmod vulnerability CVSS: 3.5 06 Dec 2018, 19:29 UTC

DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.

CVE-2018-19892 domainmod vulnerability CVSS: 3.5 06 Dec 2018, 03:29 UTC

DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.

CVE-2018-19752 domainmod vulnerability CVSS: 3.5 29 Nov 2018, 22:29 UTC

DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.

CVE-2018-19751 domainmod vulnerability CVSS: 3.5 29 Nov 2018, 22:29 UTC

DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.

CVE-2018-19750 domainmod vulnerability CVSS: 3.5 29 Nov 2018, 22:29 UTC

DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.

CVE-2018-19749 domainmod vulnerability CVSS: 3.5 29 Nov 2018, 22:29 UTC

DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.

CVE-2018-19137 domainmod vulnerability CVSS: 4.3 09 Nov 2018, 19:29 UTC

DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.

CVE-2018-19136 domainmod vulnerability CVSS: 4.3 09 Nov 2018, 19:29 UTC

DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.

CVE-2018-11559 domainmod vulnerability CVSS: 3.5 30 May 2018, 04:29 UTC

DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.

CVE-2018-11558 domainmod vulnerability CVSS: 3.5 30 May 2018, 04:29 UTC

DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.

CVE-2018-11404 domainmod vulnerability CVSS: 4.3 24 May 2018, 07:29 UTC

DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.

CVE-2018-11403 domainmod vulnerability CVSS: 3.5 24 May 2018, 07:29 UTC

DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.