CVE Tools

Document Management System

13 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Document Management System, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Document Management System CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Document Management System CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-051
2025-060
2025-071
2025-081
2025-091
2025-101
2025-110
2025-120
2026-010
2026-026
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical18%
  • High538%
  • Medium754%

Latest CVEs

The 13 most recently published vulnerabilities affecting Document Management System.

  1. CVE-2026-3153itsourcecode Document Management System register.php sql injection7.3
  2. CVE-2026-3133itsourcecode Document Management System Login loging.php sql injection7.3
  3. CVE-2026-3069itsourcecode Document Management System edtlbls.php sql injection7.3
  4. CVE-2026-3068itsourcecode Document Management System deluser.php sql injection7.3
  5. CVE-2026-24323Multiple vulnerabilities in BSP Applications of SAP Document Management System6.1
  6. CVE-2026-0505Multiple vulnerabilities in BSP Applications of SAP Document Management System6.1
  7. CVE-2025-11948Excellent Infotek|Document Management System - Arbitrary File Upload9.8
  8. CVE-2025-56289code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field ...5.4
  9. CVE-2025-8433code-projects Document Management System dell.php unlink path traversal5.4
  10. CVE-2025-8171code-projects Document Management System insert.php unrestricted upload6.3
  11. CVE-2025-46448WordPress Document Management System plugin <= 1.24 - Cross Site Scripting (XSS) Vulnerability7.1
  12. CVE-2024-6803itsourcecode Document Management System insert.php sql injection5.5
  13. CVE-2024-6014itsourcecode Document Management System edithis.php sql injection6.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store