CVE-2024-28715: Html-Js Doracms
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.
Affected products
- Html-Js Doracms: up to and including 2.18
Published 2024-03-19. Last modified 2026-06-17.