- How many CVEs does dotCMS have?
- dotCMS has 61 published CVE records since 2008, including 4 in the last two years.
- How many dotCMS CVEs are in CISA KEV?
- Yes — 1 of dotCMS's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which dotCMS products have the most CVEs?
- The dotCMS products with the most published CVEs are dotCMS, core, dotCMS core, com.dotcms:dotcms, dotCMS Cloud Services (dCS).
- What are the most common weakness types in dotCMS CVEs?
- dotCMS's CVEs most often map to these CWE weakness types: CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-338 (Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)).
- Are there public exploits for dotCMS vulnerabilities?
- Yes — 8 of dotCMS's CVEs have a known public exploit.
- How many critical dotCMS vulnerabilities are there?
- dotCMS has 10 critical and 20 high-severity CVEs.
- What is the average severity of dotCMS CVEs?
- The average CVSS base score across dotCMS's scored CVEs is 7.0.