CVE-2020-18220: Html-Js Doracms

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.

Affected products

  • Html-Js Doracms: up to and including 2.1.1

Published 2021-05-20. Last modified 2026-06-17.