CVE-2018-16980: dotCMS

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.

Affected products

  • dotCMS dotCMS: version 5.0.1 only

Published 2018-09-12. Last modified 2026-06-17.