doorgets CVE Vulnerabilities & Metrics

Focus on doorgets vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About doorgets Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with doorgets. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total doorgets CVEs: 23
Earliest CVE date: 11 Feb 2014, 17:55 UTC
Latest CVE date: 30 Apr 2019, 20:29 UTC

Latest CVE reference: CVE-2019-11626

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical doorgets CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.28

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 23
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS doorgets CVEs

These are the five CVEs with the highest CVSS scores for doorgets, sorted by severity first and recency.

All CVEs for doorgets

CVE-2019-11626 doorgets vulnerability CVSS: 5.0 30 Apr 2019, 20:29 UTC

routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/index.php?uri=1234%5c request.

CVE-2019-11625 doorgets vulnerability CVSS: 4.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/emailingRequest.php. A remote background administrator privilege user (or a user with permission to manage emailing) could exploit the vulnerability to obtain database sensitive information.

CVE-2019-11624 doorgets vulnerability CVSS: 5.5 30 Apr 2019, 20:29 UTC

doorGets 7.0 has an arbitrary file deletion vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote background administrator privilege user can exploit this vulnerability to delete arbitrary files.

CVE-2019-11623 doorgets vulnerability CVSS: 4.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=siteweb. A remote background administrator privilege user (or a user with permission to manage configuration siteweb) could exploit the vulnerability to obtain database sensitive information.

CVE-2019-11622 doorgets vulnerability CVSS: 4.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_edit_titre.

CVE-2019-11621 doorgets vulnerability CVSS: 4.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=network. A remote background administrator privilege user (or a user with permission to manage network configuration) could exploit the vulnerability to obtain database sensitive information.

CVE-2019-11620 doorgets vulnerability CVSS: 4.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_add_titre.

CVE-2019-11619 doorgets vulnerability CVSS: 4.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=analytics. A remote background administrator privilege user (or a user with permission to manage configuration analytics) could exploit the vulnerability to obtain database sensitive information.

CVE-2019-11618 doorgets vulnerability CVSS: 7.5 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification of articles via an H0XZlT44FcN1j9LTdFc5XRXhlF30UaGe1g3cZY6i1K9 access_token in a uri=blog&action=index&controller=blog action to /api/index.php.

CVE-2019-11617 doorgets vulnerability CVSS: 6.8 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modification.

CVE-2019-11616 doorgets vulnerability CVSS: 5.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php. A remote unauthenticated attacker could exploit this vulnerability to obtain the administrator password.

CVE-2019-11615 doorgets vulnerability CVSS: 6.5 30 Apr 2019, 20:29 UTC

/fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upload backdoor files to control the server.

CVE-2019-11614 doorgets vulnerability CVSS: 5.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attacker could exploit the vulnerability to obtain database sensitive information.

CVE-2019-11613 doorgets vulnerability CVSS: 4.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php. A remote normal registered user could exploit the vulnerability to obtain database sensitive information.

CVE-2019-11612 doorgets vulnerability CVSS: 6.4 30 Apr 2019, 20:29 UTC

doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php. A remote unauthenticated attacker can exploit this vulnerability to delete arbitrary files.

CVE-2019-11611 doorgets vulnerability CVSS: 5.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

CVE-2019-11610 doorgets vulnerability CVSS: 5.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

CVE-2019-11609 doorgets vulnerability CVSS: 6.4 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information or make the server unserviceable.

CVE-2019-11608 doorgets vulnerability CVSS: 6.4 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information or make the server unserviceable.

CVE-2019-11607 doorgets vulnerability CVSS: 5.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

CVE-2019-11606 doorgets vulnerability CVSS: 5.0 30 Apr 2019, 20:29 UTC

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

CVE-2018-20064 doorgets vulnerability CVSS: 5.0 11 Dec 2018, 20:29 UTC

doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&action=edit&name=doorgets&file=../../1.txt%00 URI with content in the theme_content_nofi parameter.

CVE-2018-11126 doorgets vulnerability CVSS: 6.8 15 May 2018, 17:29 UTC

dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account.

CVE-2014-1459 doorgets vulnerability CVSS: 6.5 11 Feb 2014, 17:55 UTC

SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_down_id parameter. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.