CVE-2024-28715: Html-Js Doracms

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.

Affected products

  • Html-Js Doracms: up to and including 2.18

Published 2024-03-19. Last modified 2026-06-17.