CVE-2019-11846: dotCMS

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.

Affected products

  • dotCMS dotCMS: version 5.1.1 only

Published 2019-05-14. Last modified 2026-06-17.