CVE-2020-18875: dotCMS
High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
Affected products
- dotCMS dotCMS: before 5.1.0 (fixed in 5.1.0)
Published 2021-08-18. Last modified 2026-06-17.