douco 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
過去の問題は主に vendor risk csrf and パス処理の欠陥 などに関し、一部は ファイル上書き を招き、vendor surface production workloads and vendor surface software deployment 関連の場面に影響します。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2026-2226 | A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | [email protected] | 2.0 | 0.36% | 2026-02-09 | 2026-04-29 |
| CVE-2024-57599 | Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php | [email protected] | 4.8 | 0.30% | 2025-02-06 | 2025-07-03 |
| CVE-2024-7917 | A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php of the component Favicon Handler. The manipulation of the argument site_favicon leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | [email protected] | 5.1 | 0.59% | 2024-08-18 | 2024-08-21 |
| CVE-2022-46438 | A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the description parameter. | [email protected] | 5.4 | 0.40% | 2023-01-13 | 2025-04-08 |
| CVE-2022-24131 | DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution. | [email protected] | 6.1 | 0.82% | 2022-03-30 | 2024-11-21 |
| CVE-2022-25574 | A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file. | [email protected] | 4.8 | 0.42% | 2022-03-25 | 2024-11-21 |
| CVE-2021-3370 | DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php. | [email protected] | 6.1 | 0.56% | 2021-12-08 | 2024-11-21 |
| CVE-2019-12564 | In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames. | [email protected] | 9.8 | 2.01% | 2019-06-03 | 2024-11-21 |
| CVE-2018-20567 | An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which install.lock cannot be read. | [email protected] | 5.3 | 1.03% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20566 | An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page. | [email protected] | 5.3 | 1.29% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20565 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter. | [email protected] | 4.8 | 0.53% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20564 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product_category.php?rec=update has XSS via the cat_name parameter. | [email protected] | 4.8 | 0.53% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20563 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/mobile.php?rec=system&act=update has XSS via the mobile_name parameter. | [email protected] | 4.8 | 0.53% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20562 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article_category.php?rec=update has XSS via the cat_name parameter. | [email protected] | 4.8 | 0.53% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20561 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article.php?rec=update has XSS via the title parameter. | [email protected] | 4.8 | 0.53% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20560 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/show.php?rec=update has XSS via the show_name parameter. | [email protected] | 4.8 | 0.53% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20559 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter. | [email protected] | 4.8 | 0.53% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20558 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/system.php?rec=update has XSS via the site_name parameter. | [email protected] | 4.8 | 0.53% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20557 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/page.php?rec=edit has XSS via the page_name parameter. | [email protected] | 4.8 | 0.53% | 2018-12-28 | 2024-11-21 |
| CVE-2018-20419 | DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account. | [email protected] | 8.8 | 0.48% | 2018-12-24 | 2024-11-21 |