dotclear CVE Vulnerabilities & Metrics

Focus on dotclear vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About dotclear Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with dotclear. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total dotclear CVEs: 12
Earliest CVE date: 01 Dec 2005, 06:03 UTC
Latest CVE date: 02 Sep 2018, 22:29 UTC

Latest CVE reference: CVE-2018-16358

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical dotclear CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.44

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 18
7.0-8.9 3
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS dotclear CVEs

These are the five CVEs with the highest CVSS scores for dotclear, sorted by severity first and recency.

All CVEs for dotclear

CVE-2018-16358 dotclear vulnerability CVSS: 3.5 02 Sep 2018, 22:29 UTC

A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.

CVE-2018-5690 dotclear vulnerability CVSS: 3.5 14 Jan 2018, 04:29 UTC

Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the nb parameter (aka the page limit number).

CVE-2018-5689 dotclear vulnerability CVSS: 3.5 14 Jan 2018, 04:29 UTC

Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the malicious user's email.

CVE-2017-6446 dotclear vulnerability CVSS: 4.3 05 Mar 2017, 21:59 UTC

XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.

CVE-2015-8832 dotclear vulnerability CVSS: 6.5 09 Feb 2017, 15:59 UTC

Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "manage their own entries and comments" permissions to execute arbitrary PHP code by uploading a file with a (1) .pht, (2) .phps, or (3) .phtml extension.

CVE-2015-8831 dotclear vulnerability CVSS: 4.3 09 Feb 2017, 15:59 UTC

Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the author name in a comment.

CVE-2016-7903 dotclear vulnerability CVSS: 4.3 04 Jan 2017, 21:59 UTC

Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.

CVE-2016-7902 dotclear vulnerability CVSS: 6.5 04 Jan 2017, 21:59 UTC

Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20.

CVE-2016-9891 dotclear vulnerability CVSS: 3.5 29 Dec 2016, 18:59 UTC

Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inject arbitrary web script or HTML via the upfiletitle or media_title parameter (aka the media title).

CVE-2016-6523 dotclear vulnerability CVSS: 4.3 09 Dec 2016, 20:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php.

CVE-2016-9268 dotclear vulnerability CVSS: 9.0 10 Nov 2016, 20:59 UTC

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

CVE-2015-5651 dotclear vulnerability CVSS: 4.3 03 Oct 2015, 22:59 UTC

Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-5316 dotclear vulnerability CVSS: 4.3 22 Sep 2014, 01:55 UTC

Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted page.

CVE-2014-3782 dotclear vulnerability CVSS: 6.0 11 Jun 2014, 14:55 UTC

Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension.

CVE-2014-3781 dotclear vulnerability CVSS: 5.8 11 Jun 2014, 14:55 UTC

The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty password in an XML-RPC request.

CVE-2014-3783 dotclear vulnerability CVSS: 6.0 22 May 2014, 15:13 UTC

SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter.

CVE-2014-1613 dotclear vulnerability CVSS: 7.5 16 May 2014, 15:55 UTC

Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.

CVE-2012-1039 dotclear vulnerability CVSS: 4.3 19 Mar 2012, 19:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.

CVE-2011-5083 dotclear vulnerability CVSS: 7.5 19 Mar 2012, 18:55 UTC

Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory.

CVE-2011-1584 dotclear vulnerability CVSS: 6.5 08 Jun 2011, 10:36 UTC

The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allows remote authenticated users to upload and execute arbitrary PHP code via the media_path or media_file parameter. NOTE: some of these details are obtained from third party information.

CVE-2009-0933 dotclear vulnerability CVSS: 4.3 17 Mar 2009, 22:30 UTC

Cross-site scripting (XSS) vulnerability in the administrative interface in Dotclear before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2008-3232 dotclear vulnerability CVSS: 9.3 18 Jul 2008, 16:41 UTC

Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images.

CVE-2007-3688 dotclear vulnerability CVSS: 2.6 11 Jul 2007, 17:30 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in DotClear 1.2.6 allow remote attackers to perform actions as arbitrary users via the (1) tool_url parameter to ecrire/tools.php and multiple fields on the (2) blogconf, (3) blogroll, (4) ecrire/redacteur.php, and (5) ecrire/user_prefs.php pages.

CVE-2007-3672 dotclear vulnerability CVSS: 4.3 10 Jul 2007, 19:30 UTC

Cross-site scripting (XSS) vulnerability in ecrire/tools.php in DotClear 1.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified form fields on the blogroll page.

CVE-2007-1989 dotclear vulnerability CVSS: 4.3 12 Apr 2007, 10:19 UTC

Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these details are obtained from third party information.

CVE-2006-3938 dotclear vulnerability CVSS: 5.0 31 Jul 2006, 22:04 UTC

DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrire/tools/blogroll/; (4) syslog/index.php, (5) thememng/index.php, (6) toolsmng/index.php, (7) utf8convert/index.php in /ecrire/tools/; (8) /ecrire/inc/connexion.php and (9) /inc/session.php; (10) class.blog.php, (11) class.blogcomment.php, (12) and class.blogpost.php in /inc/classes/; (13) append.php, (14) class.xblog.php, (15) class.xblogcomment.php, and (16) class.xblogpost.php in /layout/; (17) form.php, (18) list.php, (19) post.php, or (20) template.php in /themes/default/, which reveal the installation path in error messages.

CVE-2006-2866 dotclear vulnerability CVSS: 5.1 06 Jun 2006, 20:06 UTC

PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a FTP URL in the blog_dc_path parameter, which passes file_exists() and is_dir() tests on PHP 5.

CVE-2005-3963 dotclear vulnerability CVSS: 7.5 02 Dec 2005, 00:03 UTC

SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie.

CVE-2005-3957 dotclear vulnerability CVSS: 10.0 01 Dec 2005, 06:03 UTC

Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.