44 Total CVEs
44 AI Analyzed
0 CISA KEV
33 Critical

Profile

0% ended up actively exploited 0 of 44 added to CISA KEV
75% rated critical (CVSS 9.0+) 33 critical, 11 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

43 CVEs in the last 12 months

Products

  • dokploy44

1 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-44 of 44 CVEs
CVE-2026-82954
Analyzed
9.9
Dokploy dokploy

Dokploy versions up to 0.29.7 contain a path traversal vulnerability in the writeTraefikConfigInPath function, allowing authenticated attackers to man...

2026-09-01
Full analysis →
CVE-2026-72902
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 are vulnerable to OS command injection via the registry testing functions, allowing authenticated users to execute arb...

2026-08-11
Full analysis →
CVE-2026-72901
Analyzed
9.9
Dokploy dokploy

Dokploy versions prior to 0.29.13 are susceptible to OS command injection via the volume backup functionality, allowing authenticated low-privilege us...

2026-08-11
Full analysis →
CVE-2026-72886
Analyzed
9.9
Dokploy dokploy

An improper privilege management vulnerability in Dokploy allows authenticated users to escalate privileges and execute arbitrary scripts as root on t...

2026-08-11
Full analysis →
CVE-2026-72882
Analyzed
9.9
Dokploy dokploy

Dokploy versions 0.28.8 and earlier are vulnerable to OS command injection via the filePath parameter, allowing authenticated users to execute arbitra...

2026-08-11
Full analysis →
CVE-2026-72880
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 contain an arbitrary file write and deletion vulnerability due to improper input validation in the certificate managem...

2026-08-11
Full analysis →
CVE-2026-72879
Analyzed
9.4
Dokploy dokploy

Dokploy versions prior to 0.29.8 are vulnerable to OS command injection via the getRegistryCommands function, allowing authenticated users to execute...

2026-08-11
Full analysis →
CVE-2026-72878
Analyzed
9.6
Dokploy dokploy

Dokploy prior to 0.29.13 is vulnerable to OS command injection via the backup and restore pipeline, allowing authenticated admins to execute arbitrary...

2026-08-11
Full analysis →
CVE-2026-72877
Analyzed
9.6
Dokploy dokploy

Dokploy versions before 0.29.13 are vulnerable to OS command injection via the dockerImage field, allowing authenticated users to execute arbitrary co...

2026-08-11
Full analysis →
CVE-2026-72876
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 contain an authorization bypass and OS command injection flaw, allowing authenticated users to manipulate server IDs a...

2026-08-11
Full analysis →
CVE-2026-72872
Analyzed
9.9
Dokploy dokploy

Dokploy improperly validates Bitbucket repository fields, allowing authenticated users to inject arbitrary OS commands into git clone operations.

2026-08-11
Full analysis →
CVE-2026-72869
Analyzed
9.9
Dokploy dokploy

An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with backup permissions to execute arbitrary commands in...

2026-08-11
Full analysis →
CVE-2026-72868
Analyzed
9.9
Dokploy dokploy

Dokploy allows a low-privileged member to execute arbitrary OS commands as root by injecting malicious input into the rclone configuration fields duri...

2026-08-11
Full analysis →
CVE-2026-72867
Analyzed
9.9
Dokploy dokploy

Dokploy versions 0.29.3 through 0.29.12 are susceptible to OS command injection due to insufficient server-side validation of git branch fields during...

2026-08-11
Full analysis →
CVE-2026-72865
Analyzed
9.9
Dokploy dokploy

Dokploy versions prior to 0.29.13 contain an OS command injection vulnerability in the compose update process, allowing authenticated users to execute...

2026-08-11
Full analysis →
CVE-2026-72864
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 are vulnerable to a missing authorization flaw in the docker-container-terminal component, allowing authenticated user...

2026-08-11
Full analysis →
CVE-2026-72863
Analyzed
9.9
Dokploy dokploy

Dokploy versions prior to 0.29.13 fail to enforce authorization checks on WebSocket handlers, allowing authenticated users to access interactive shell...

2026-08-11
Full analysis →
CVE-2026-72862
Analyzed
9.9
Dokploy dokploy

Dokploy contains an OS command injection vulnerability in its database service deployment functions, allowing authenticated users to execute arbitrary...

2026-08-11
Full analysis →
CVE-2026-72740
Analyzed
9.9
Dokploy dokploy

An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with deployment permissions to execute arbitrary commands...

2026-08-11
Full analysis →
CVE-2026-72738
Analyzed
9.9
Dokploy dokploy

An OS command injection vulnerability in the Dokploy backup endpoint allows authenticated users to execute arbitrary commands on the host server.

2026-08-11
Full analysis →
CVE-2026-72737
Analyzed
9.6
Dokploy dokploy

A cross-tenant authorization bypass in Dokploy versions 0.29.8 and earlier allows authenticated users with backup permissions to access or poison back...

2026-08-11
Full analysis →
CVE-2026-72736
Analyzed
9.9
Dokploy dokploy

Dokploy contains a command injection vulnerability in its registry credential and Docker Swarm management endpoints, allowing authenticated users to e...

2026-08-11
Full analysis →
CVE-2026-72735
Analyzed
9.9
Dokploy dokploy

An incomplete fix for a previous vulnerability allows authenticated users to perform OS command injection on remote servers managed by Dokploy through...

2026-08-11
Full analysis →
CVE-2026-72733
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 are vulnerable to OS command injection in the backup restore functionality, allowing authenticated users to execute ar...

2026-08-11
Full analysis →
CVE-2026-45663
Analyzed
9.9
Dokploy dokploy

Dokploy contains a command injection vulnerability in its Docker file upload functionality that allows authenticated users to execute arbitrary OS com...

2026-05-30
Full analysis →
CVE-2026-45661
Analyzed
9.9
Dokploy dokploy

A path traversal vulnerability in Dokploy allows authenticated users to write arbitrary files to the host or remote servers during application deploym...

2026-05-30
Full analysis →
CVE-2026-45633
Analyzed
9.9
Dokploy dokploy

Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint that allows authenticated users to execute arbitra...

2026-05-30
Full analysis →
CVE-2026-45632
Analyzed
9.9
Dokploy dokploy

A broken access control vulnerability in the Dokploy schedule router allows authenticated users to manage schedules belonging to other organizations,...

2026-05-30
Full analysis →
CVE-2026-45631
Analyzed
10
Dokploy dokploy

A hardcoded authentication secret in Dokploy allows unauthenticated attackers to forge JWTs, gain administrative access, and execute commands on the h...

2026-05-30
Full analysis →
CVE-2026-45629
Analyzed
9.9
Dokploy dokploy

An OS command injection vulnerability in the Dokploy /listen-deployment WebSocket endpoint allows authenticated users to execute arbitrary commands on...

2026-05-30
Full analysis →
CVE-2026-27130
Analyzed
9.9
Dokploy dokploy

Dokploy 0.26.6 and below contain an OS command injection vulnerability in the appName parameter, allowing authenticated attackers to execute arbitrary...

2026-05-19
Full analysis →
CVE-2026-24841
Analyzed
9.9
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokpl...

2026-01-28
Full analysis →
CVE-2025-53825
Analyzed
9.4
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy...

2025-07-14
Full analysis →