Dokan Inc Dokan vulnerabilities
5 known vulnerabilities affecting dokan_inc/dokan.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-24359P2HIGHCVSS 8.8≤ 4.2.42026-03-25
CVE-2026-24359 [HIGH] CWE-288 CVE-2026-24359: Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-li
Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4.
nvd
CVE-2026-49780P3HIGHCVSS 8.8≥ n/a, ≤ 5.0.22026-06-15
CVE-2026-49780 [HIGH] CWE-266 CVE-2026-49780: Customer Privilege Escalation in Dokan <= 5.0.2 versions.
Customer Privilege Escalation in Dokan <= 5.0.2 versions.
nvd
CVE-2025-53425P3HIGHCVSS 7.2≤ 4.1.32025-10-22
CVE-2025-53425 [HIGH] CWE-266 CVE-2025-53425: Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escala
Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.3.
nvd
CVE-2026-66699P4MEDIUMCVSS 5.3≥ n/a, ≤ 5.0.102026-08-06
CVE-2026-66699 [MEDIUM] CWE-862 CVE-2026-66699: Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
nvd
CVE-2026-57706P4HIGHCVSS 7.1≤ 5.0.62026-07-13
CVE-2026-57706 [HIGH] CWE-79 CVE-2026-57706: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6.
nvd