CVE Tools

Dokploy

48 CVEs tracked since 2026. Since May 2026, none of them reached CISA KEV.

Dokploy CVEs per month

May 2026 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Dokploy CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-05110
2026-06null or fewer
2026-07null or fewer
2026-08370

Products

The products that kept showing up in Dokploy's monthly top three, with their CVEs summed over those months.

  1. Dokploy482 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Dokploy.

  1. CVE-2026-93425Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root9.9
  2. CVE-2026-86059Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one9.6
  3. CVE-2026-45791Dokploy: Password Change Does Not Revoke Active Sessions5.9
  4. CVE-2026-45790Dokploy: Invitation Role Escalation Allows Organization Takeover8.0
  5. CVE-2026-72902Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById9.9
  6. CVE-2026-72901Dokploy: Remote Code Execution via volume-backup9.9
  7. CVE-2026-72886Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632)9.9
  8. CVE-2026-72885Dokploy: Authenticated Command Injection in Dokploy Dockerfile Builder—
  9. CVE-2026-72884Dokploy: Command Injection via Compose Custom Command—
  10. CVE-2026-72883Dokploy: WebSocket Terminal Missing Service-Level Access Control8.8
  11. CVE-2026-72882Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers9.9
  12. CVE-2026-72881Dokploy: Command Injection via database credentials in backup/restore commands—
  13. CVE-2026-72880Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath`9.9
  14. CVE-2026-72879Dokploy: Command Injection via Registry Credentials in Swarm Upload—
  15. CVE-2026-72878Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments9.6

The record

Peak rank
#32 in Aug 2026
Busiest month shown
Aug 2026, 37 CVEs
Months with a KEV entry
0 since May 2026
Monthly snapshots
2 since 2026
Dokploy's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store