CVE-2022-26352CISA KEVEPSS p99.8%
CVE-2022-26352dotCMS Unrestricted Upload of File Vulnerability
dotCMS / dotCMS
Description
dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.
Scoring
| EPSS | 91.50% probability of exploitation · percentile 99.8% · 2026-06-15T12:03:41Z |
CISA KEV entry
Added to KEV: 2022-08-25
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | dotCMS Unrestricted Upload of File Vulnerabilitykev-cve-2022-26352 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.