CVE-2017-6446: Dotclear

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.

Affected products

Published 2017-03-05. Last modified 2026-06-17.