CVEs we hold for Dokploy
Records whose assigning authority named Dokploy as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-72902Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryByIddokploy
CVE-2026-72886Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules…dokploy
CVE-2026-72882Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed serversdokploy
CVE-2026-72880Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath`dokploy
CVE-2026-72878Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell argumentsdokploy
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*dokploy
CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFiledokploy
CVE-2026-72873Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged service readers via `application.one`dokploy
CVE-2026-72872Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`dokploy
CVE-2026-72869Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEdokploy
CVE-2026-72868Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injectiondokploy
CVE-2026-72867Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment…dokploy
CVE-2026-72864Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers)dokploy
CVE-2026-72863Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker hostdokploy
CVE-2026-72862Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCEdokploy
CVE-2026-72740Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan`dokploy
CVE-2026-72738Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameterdokploy
CVE-2026-72737Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backupsdokploy
CVE-2026-72736Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCEdokploy
CVE-2026-72735Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote executiondokploy
CVE-2026-72734Dokploy: Cross-organization authorization bypass in server.remove allows deletion of another organization's server…dokploy
CVE-2026-72733Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restoredokploy
CVE-2026-45662Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)dokploy
CVE-2026-45630Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statementdokploy
CVE-2026-45629Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpointdokploy
CVE-2026-43917Dokploy: Cross-Organization IDOR - Multiple tRPC endpoints missing activeOrganizationId validationdokploy
CVE-2026-24841Dokploy Vulnerable to Authenticated Remote Code Execution via Command Injection in Docker Container Terminal WebSocket…dokploy
CVE-2026-24840Dokploy uses hardcoded credentials in installation script, which could result in database accessdokploy
CVE-2026-24839Dokploy has a clickjacking vulnerability - Missing X-Frame-Options and CSP frame-ancestors headersdokploy
CVE-2025-53375Dokploy allows attackers to read any file that the Traefik process user can accessdokploy
56 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.