← Vulnerability feed

Vulnerability record · CVE-2024-58281 · published 10 December 2025

CVE-2024-58281: Dotclear unrestricted file upload vulnerability

Dotclear · Dotclear

Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload process by crafting a PHP shell with a command execution form to gain system access through the uploaded file.

8.7 CVSS 4.0 High EPSS 0.94% · top 40.5% CWE-434 · Unrestricted file upload
8.7CVSS 4.0 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 1 tagged exploit
26 Sep 2026Last modified by NVD

Description

Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload process by crafting a PHP shell with a command execution form to gain system access through the uploaded file.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-58281 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3957Dotclear vulnerabilityUnspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.EPSS 1.6%9.3CVE-2008-3232Dotclear code injection vulnerabilityUnrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary co…EPSS 4.6%8.8CVE-2015-8832Dotclear improper access control vulnerabilityMultiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage th…EPSS 2.6%8.8CVE-2016-7902Dotclear unrestricted file upload vulnerabilityUnrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to…EPSS 3.0%8.7CVE-2023-53952Dotclear unrestricted file upload vulnerabilityDotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension…EPSS 1.1%7.5CVE-2014-1613Dotclear code injection vulnerabilityDotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected p…EPSS 2.3%7.5CVE-2011-5083Dotclear permissions and access controls vulnerabilityUnrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uplo…EPSS 3.3%7.5CVE-2005-3963Dotclear vulnerabilitySQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2024-58281), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.