CVE-2026-3795Disclosure(html-js / doracms)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v1.js. Performing a manipulation results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Exploit / PoC references
Vendor / third-party advisories
Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • doracms

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-09); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
doracms

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-09: 3Mentions · 2026-03-10: 1Technical Details · 2026-03-09: 303-0903-10
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-093
Disclosure2General1
2026-03-101
General1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3795 Path Traversal Vulnerability in DoraCMS 3.0.x via createFileBypath Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3795

    Post summary

    A brief announcement of a path traversal vulnerability in DoraCMS 3.0.x via the createFileBypath function, with a link to detailed vulnerability information.

    0001058
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3795 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3795 #CVE-2026-3795 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/OKjxPRZ3iY

    Post summary

    The tweet merely announces the CVE-2026‑3795 with its severity score and a reference link, lacking detailed technical information or actionable insights.

    0000023
    93 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-3795 A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v1.js. Performing a … https://www.cve.org/CVERecord?id=CVE-2026-3795 ----- Traducción: CVE-2026-3795 Se … http://infoflow.cloud`

    Post summary

    The text spotlights a newly discovered CVE in DoraCMS, mentioning the affected function and file but lacking detailed technical exploitation or mitigation information.

    0000028
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3795 A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v1.js. Performing a … https://www.cve.org/CVERecord?id=CVE-2026-3795

    Post summary

    A new vulnerability, CVE‑2026‑3795, has been disclosed affecting DoraCMS 3.0.x's createFileBypath function; no exploit, PoC, patch, or active exploitation details are provided.

    00000143
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphtml-jsdoracms---

Explore more