CVE-2020-35274: dotCMS

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.

Affected products

  • dotCMS dotCMS: version 20.11 only

Published 2020-12-21. Last modified 2026-07-09.