Dokploy versions up to 0.29.7 contain a path traversal vulnerability in the writeTraefikConfigInPath function, allowing authenticated attackers to man...
Dokploy CVEs
44 high and critical vulnerabilities covered by CVE Brief since 2025-07-14, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
43 CVEs in the last 12 months
Products
- dokploy44
1 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Dokploy versions before 0.29.13 are vulnerable to OS command injection via the registry testing functions, allowing authenticated users to execute arb...
Dokploy versions prior to 0.29.13 are susceptible to OS command injection via the volume backup functionality, allowing authenticated low-privilege us...
An improper privilege management vulnerability in Dokploy allows authenticated users to escalate privileges and execute arbitrary scripts as root on t...
Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy versions 0.28.8 and earlier are vulnerable to OS command injection via the filePath parameter, allowing authenticated users to execute arbitra...
Dokploy versions before 0.29.13 contain an arbitrary file write and deletion vulnerability due to improper input validation in the certificate managem...
Dokploy versions prior to 0.29.8 are vulnerable to OS command injection via the getRegistryCommands function, allowing authenticated users to execute...
Dokploy prior to 0.29.13 is vulnerable to OS command injection via the backup and restore pipeline, allowing authenticated admins to execute arbitrary...
Dokploy versions before 0.29.13 are vulnerable to OS command injection via the dockerImage field, allowing authenticated users to execute arbitrary co...
Dokploy versions before 0.29.13 contain an authorization bypass and OS command injection flaw, allowing authenticated users to manipulate server IDs a...
Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy improperly validates Bitbucket repository fields, allowing authenticated users to inject arbitrary OS commands into git clone operations.
Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy is a free, self-hostable Platform as a Service (PaaS)
An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with backup permissions to execute arbitrary commands in...
Dokploy allows a low-privileged member to execute arbitrary OS commands as root by injecting malicious input into the rclone configuration fields duri...
Dokploy versions 0.29.3 through 0.29.12 are susceptible to OS command injection due to insufficient server-side validation of git branch fields during...
Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy versions prior to 0.29.13 contain an OS command injection vulnerability in the compose update process, allowing authenticated users to execute...
Dokploy versions before 0.29.13 are vulnerable to a missing authorization flaw in the docker-container-terminal component, allowing authenticated user...
Dokploy versions prior to 0.29.13 fail to enforce authorization checks on WebSocket handlers, allowing authenticated users to access interactive shell...
Dokploy contains an OS command injection vulnerability in its database service deployment functions, allowing authenticated users to execute arbitrary...
An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with deployment permissions to execute arbitrary commands...
An OS command injection vulnerability in the Dokploy backup endpoint allows authenticated users to execute arbitrary commands on the host server.
A cross-tenant authorization bypass in Dokploy versions 0.29.8 and earlier allows authenticated users with backup permissions to access or poison back...
Dokploy contains a command injection vulnerability in its registry credential and Docker Swarm management endpoints, allowing authenticated users to e...
An incomplete fix for a previous vulnerability allows authenticated users to perform OS command injection on remote servers managed by Dokploy through...
Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy versions before 0.29.13 are vulnerable to OS command injection in the backup restore functionality, allowing authenticated users to execute ar...
Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy contains a command injection vulnerability in its Docker file upload functionality that allows authenticated users to execute arbitrary OS com...
Dokploy is a free, self-hostable Platform as a Service (PaaS)
A path traversal vulnerability in Dokploy allows authenticated users to write arbitrary files to the host or remote servers during application deploym...
Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint that allows authenticated users to execute arbitra...
A broken access control vulnerability in the Dokploy schedule router allows authenticated users to manage schedules belonging to other organizations,...
A hardcoded authentication secret in Dokploy allows unauthenticated attackers to forge JWTs, gain administrative access, and execute commands on the h...
An OS command injection vulnerability in the Dokploy /listen-deployment WebSocket endpoint allows authenticated users to execute arbitrary commands on...
Dokploy 0.26.6 and below contain an OS command injection vulnerability in the appName parameter, allowing authenticated attackers to execute arbitrary...
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokpl...
Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy...