Vulnerability Database

314,433

Total vulnerabilities in the database

CVE-2014-5316

Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted page.

  • Published: Sep 22, 2014
  • Updated: Nov 9, 2025
  • CVE: CVE-2014-5316
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
dotclear / dotclear 2.0-beta_7 2.0-beta_7.x
dotclear / dotclear 2.0-beta_5.4 2.0-beta_5.4.x
dotclear / dotclear 2.2.1 2.2.1.x
dotclear / dotclear 2.0-beta_5.2 2.0-beta_5.2.x
dotclear / dotclear 2.1 2.1.x
dotclear / dotclear 2.0.1 2.0.1.x
dotclear / dotclear 2.4.4 2.4.4.x
dotclear / dotclear 2.0.2 2.0.2.x
dotclear / dotclear 2.1.4 2.1.4.x
dotclear / dotclear 2.0 2.0.x
dotclear / dotclear 2.4.3 2.4.3.x
dotclear / dotclear 2.2.2 2.2.2.x
dotclear / dotclear 2.6-rc 2.6-rc.x
dotclear / dotclear 2.5.2 2.5.2.x
dotclear / dotclear 2.0-beta_3 2.0-beta_3.x
dotclear / dotclear 2.3.0 2.3.0.x
dotclear / dotclear 2.1.1 2.1.1.x
dotclear / dotclear 2.3.1 2.3.1.x
dotclear / dotclear 2.6.1 2.6.1.x
dotclear / dotclear 2.0-beta_4 2.0-beta_4.x
dotclear / dotclear 2.0-rc1 2.0-rc1.x
dotclear / dotclear 2.5.1 2.5.1.x
dotclear / dotclear 2.4.2 2.4.2.x
dotclear / dotclear 2.1.5 2.1.5.x
dotclear / dotclear 2.1.7 2.1.7.x
dotclear / dotclear 2.0-beta_2 2.0-beta_2.x
dotclear / dotclear 2.2.3 2.2.3.x
dotclear / dotclear 2.0-beta_6 2.0-beta_6.x
dotclear / dotclear 2.5.3 2.5.3.x
dotclear / dotclear 2.6 2.6.x
dotclear / dotclear 2.0-rc2 2.0-rc2.x
dotclear / dotclear 2.2 2.2.x
dotclear / dotclear 2.1.6 2.1.6.x
dotclear / dotclear 2.1.3 2.1.3.x
dotclear / dotclear - 2.6.3.x
dotclear / dotclear 2.5.0 2.5.0.x
dotclear / dotclear 2.6.2 2.6.2.x