dokploy
Cloud & SaaScommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting dokploy.
- CVE-2026-45791Dokploy: Password Change Does Not Revoke Active Sessions5.9
- CVE-2026-45790Dokploy: Invitation Role Escalation Allows Organization Takeover8.0
- CVE-2026-72902Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById9.9
- CVE-2026-72901Dokploy: Remote Code Execution via volume-backup9.9
- CVE-2026-72886Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632)9.9
- CVE-2026-72883Dokploy: WebSocket Terminal Missing Service-Level Access Control8.8
- CVE-2026-72882Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers9.9
- CVE-2026-72880Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath`9.9
- CVE-2026-72878Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments9.6
- CVE-2026-72877Dokploy: Command Injection via dockerImage in buildRemoteDocker9.6
- CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*9.9
- CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile8.8
- CVE-2026-72873Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged service readers via `application.one`6.5
- CVE-2026-72872Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`9.9
- CVE-2026-72871Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback7.5