CVE-2026-3794General(html-js / doracms)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Exploit / PoC references
Vendor / third-party advisories
Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • doracms

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-09); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
doracms

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-09: 3Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0903-1003-1203-13
Signal classification2 categories
General
466.7%
Disclosure
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-093
Disclosure1General2
2026-03-101
General1
2026-03-121
General1
2026-03-131
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3794 (CVSS:6.9, HIGH) is Analyzed. A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1..https://nvd.nist.gov/vuln/detail/CVE-2026-3794 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces that CVE-2026-3794, a high‑severity vulnerability in Doramart DoraCMS 3.0.x, has been analyzed and identified, but provides no additional exploitation or mitigation details.

    0000030
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-3794 (CVSS:6.9, HIGH) is Analyzed. A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1..https://nvd.nist.gov/vuln/detail/CVE-2026-3794 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post lists CVE-2026-3794 with its CVSS score and a brief note about an unknown processing issue in DoraCMS, but offers no deeper technical, exploit, or mitigation details.

    0000024
    172 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3794 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3794 #CVE-2026-3794 #CVE #High  #CyberSecurity #InfoSec https://t.co/8N3qMqEkrG

    Post summary

    The tweet simply announces CVE‑2026‑3794 with basic severity information, without providing evidence of proof of concept, exploitation, patches, or technical specifics.

    0000031
    93 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-3794 A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such mani… https://www.cve.org/CVERecord?id=CVE-2026-3794 ----- Traducción: CVE-2026-3794 Se … http://infoflow.cloud`

    Post summary

    The post briefly announces CVE-2026-3794, noting it affects the Email API’s /api/v1/mail/send endpoint in DoraCMS 3.0.x, but provides no PoC, exploit, or mitigation details.

    0000025
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3794 A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such mani… https://www.cve.org/CVERecord?id=CVE-2026-3794

    Post summary

    The text reports the identification of CVE-2026-3794 affecting doramart DoraCMS 3.0.x's Email API, with no additional details on exploitation or remediation.

    00000147
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-3794 - doramart - DoraCMS - https://www.redpacketsecurity.com/cve-alert-cve-2026-3794-doramart-doracms/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3794 #doramart #doracms

    Post summary

    The tweet merely references a CVE alert with a link to an external site, offering no specific details or actionable information within the tweet itself.

    00000102
    3.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphtml-jsdoracms---

Explore more