← Vulnerability feed

Vulnerability record · CVE-2022-45783 · published 1 February 2023

CVE-2022-45783: Dotcms path traversal vulnerability

Dotcms · Dotcms

An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote Code Execution.

6.5 CVSS 3.1 Medium EPSS 8.5% · top 5.2% CWE-22 · Path traversal
6.5CVSS 3.1 base score
8.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote Code Execution.

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-45783 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26352dotCMS ContentResource API path traversal enables unauthenticated file upload RCEThe ContentResource API in dotCMS 3.0 through 22.02 fails to sanitize the filename in multipart form uploads, allowing directory traversal that write…KEVEPSS 92%analysed9.8CVE-2020-19138Dotcms unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src…EPSS 5.7%9.8CVE-2020-6754dotCMS directory traversal and unrestricted file upload enable RCEdotCMS before 5.2.4 is vulnerable to directory traversal that breaks access control on the $TOMCAT_HOME/webapps/ROOT/assets directory. Attackers can …EPSS 95%analysed9.8CVE-2017-5344Dotcms sql injection vulnerabilityAn issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet pe…EPSS 6.3%9.8CVE-2016-2355Dotcms sql injection vulnerabilitySQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter…EPSS 2.1%9.8CVE-2016-8902Dotcms sql injection vulnerabilitySQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQ…EPSS 2.8%9.4CVE-2025-11165Dotcms sql injection vulnerabilityA sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to byp…EPSS 0.31%8.8CVE-2022-45782Dotcms vulnerabilityAn issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm f…EPSS 0.64%

Source: NIST National Vulnerability Database (record CVE-2022-45783), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.