Known Vulnerabilities for products from Domainmod

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Domainmod".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2020-35358 json DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both ses... 9.8 - CRITICAL 2021-03-15 2021-03-18
CVE-2020-20990 json A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute ... 5.4 - MEDIUM 2021-08-12 2021-08-16
CVE-2020-20989 json A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs. 4.3 - MEDIUM 2021-08-12 2021-08-18
CVE-2020-20988 json A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to ... 5.4 - MEDIUM 2021-08-12 2021-08-16
CVE-2020-12735 json reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover. 9.8 - CRITICAL 2020-05-08 2020-05-12
CVE-2019-1010096 json DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can ch... 8.8 - HIGH 2019-07-18 2019-10-30
CVE-2019-1010095 json DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can ad... 8.8 - HIGH 2019-07-18 2019-10-30
CVE-2019-1010094 json domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can ch... 8.8 - HIGH 2019-07-18 2019-07-19
CVE-2019-15811 json In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS. 6.1 - MEDIUM 2019-08-29 2019-09-03
CVE-2019-9080 json DomainMOD before 4.14.0 uses MD5 without a salt for password storage. 7.5 - HIGH 2020-10-20 2021-07-21
CVE-2018-1000856 json DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) vulner... 4.8 - MEDIUM 2018-12-20 2019-01-07
CVE-2018-20011 json DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. 4.8 - MEDIUM 2018-12-10 2019-02-26
CVE-2018-20010 json DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field. 4.8 - MEDIUM 2018-12-10 2019-02-26
CVE-2018-20009 json DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field. 4.8 - MEDIUM 2018-12-10 2019-02-26
CVE-2018-19915 json DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field. 4.8 - MEDIUM 2018-12-06 2019-02-26
CVE-2018-19914 json DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field. 4.8 - MEDIUM 2018-12-06 2019-02-26
CVE-2018-19913 json DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field. 4.8 - MEDIUM 2018-12-06 2018-12-21
CVE-2018-19892 json DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field. 4.8 - MEDIUM 2018-12-06 2018-12-21
CVE-2018-19752 json DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar. 4.8 - MEDIUM 2018-11-29 2018-12-21
CVE-2018-19751 json DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields. 4.8 - MEDIUM 2018-11-29 2018-12-21

Known software with vulnerabilities from Domainmod

Type Vendor Product Version
ApplicationDomainmodDomainmod0.1.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report