dotCMS vendor intelligence

dotCMS Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting dotCMS products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse dotCMS KEVs Full KEV feed
Total KEVs
2
Known exploited vulnerabilities affecting dotCMS products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
dotCMS KEV with sensor-observed exploitation activity

Review dotCMS exploitation against the products you run

Review exploited dotCMS vulnerabilities against the products you run. CISA KEV coverage is shown below.

50%
Covered by CISA
50%
Beyond CISA
2
Product families

Attested dotCMS vulnerabilities

2 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-8054

Unauthenticated SQL Injection in dotCMS Publish Audit API

dotCMS Core Confirmed Beyond CISA 27 Jun 2026
CVE-2022-26352

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose...

dotCMS Confirmed In CISA 25 Aug 2022

Showing 2 of 2 on this page (2 dotCMS known exploited vulnerabilities).

Recurring weakness patterns

Neutralization account for one mapped occurrence across this dotCMS KEV portfolio.

Browse all KEVs →