Mauricio Siu
8 exploits
Active since Jul 2025
Dokploy has Command Injection in its Service Operations
CVSS 9.9
dokploy < 0.26.6 - Authenticated OS Command Injection via WebSocket Endpoint Parameters
CVSS 9.9
dokploy < 0.23.7 - Authenticated Exposure of Private Personal Information via user.one Endpoint
CVSS 4.3
dokploy < 0.23.7 - Authenticated Path Traversal
CVSS 6.5
Dokploy <0.23.7 - Command Injection
CVSS 8.8
dokploy < 0.24.3 - Unauthenticated Remote Code Execution via Preview Deployment
CVSS 9.4
dokploy < 0.26.6 - Clickjacking via Missing Frame-Busting Headers
CVSS 4.7
dokploy < 0.26.6 - Use of Hard-coded Credentials in Installation Script
CVSS 8.0