← Vulnerability feed

Vulnerability record · CVE-2021-35358 · published 9 July 2021

CVE-2021-35358: Dotcms cross-site scripting vulnerability

Dotcms · Dotcms

A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' and 'Filename' parameters.

4.8 CVSS 3.1 Medium EPSS 0.50% · top 59.8% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score, v2 3.5
0.50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' and 'Filename' parameters.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/dotCMS/core/issues/20540 ExploitIssue TrackingThird Party Advisory
https://github.com/dotCMS/core/issues/20540 ExploitIssue TrackingThird Party Advisory

Track CVE-2021-35358 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26352dotCMS ContentResource API path traversal enables unauthenticated file upload RCEThe ContentResource API in dotCMS 3.0 through 22.02 fails to sanitize the filename in multipart form uploads, allowing directory traversal that write…KEVEPSS 92%analysed9.8CVE-2020-19138Dotcms unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src…EPSS 5.7%9.8CVE-2020-6754dotCMS directory traversal and unrestricted file upload enable RCEdotCMS before 5.2.4 is vulnerable to directory traversal that breaks access control on the $TOMCAT_HOME/webapps/ROOT/assets directory. Attackers can …EPSS 95%analysed9.8CVE-2017-5344Dotcms sql injection vulnerabilityAn issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet pe…EPSS 6.3%9.8CVE-2016-2355Dotcms sql injection vulnerabilitySQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter…EPSS 2.1%9.8CVE-2016-8902Dotcms sql injection vulnerabilitySQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQ…EPSS 2.8%9.4CVE-2025-11165Dotcms sql injection vulnerabilityA sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to byp…EPSS 0.31%8.8CVE-2022-45782Dotcms vulnerabilityAn issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm f…EPSS 0.64%

Source: NIST National Vulnerability Database (record CVE-2021-35358), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.