Dokploy
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 37 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 7, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById
Dokploy: Remote Code Execution via volume-backup
Dokploy: Command Injection via Compose Custom Command
Dokploy: WebSocket Terminal Missing Service-Level Access Control
Dokploy: Command Injection via dockerImage in buildRemoteDocker
Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*
Dokploy: Command Injection via Unescaped Git URL in Clone Commands
Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`
Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback
Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE
Monitor Dokploy in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.