Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

dokaninc — Vulnerabilities & Security Advisories 7

Browse all 7 CVE security advisories affecting dokaninc. AI-powered Chinese analysis, POCs, and references for each vulnerability.

DokanInc develops file system filter drivers that enable Windows applications to create custom virtual file systems, primarily used for cloud storage integration and virtual drive management. Historically, their products have been associated with remote code execution vulnerabilities due to insufficient input validation in driver communication, as well as privilege escalation flaws through improper access controls. The three documented CVEs reveal patterns of buffer overflows and race conditions in kernel-mode components. While no major public security incidents have been reported, the persistent nature of these vulnerabilities in driver-level software presents significant risks, as compromised kernel components can lead to complete system compromise with elevated privileges.

CVE ID Title CVSS Severity Published
CVE-2026-8761 Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-862 8.8 High 2026-08-05
CVE-2026-11783 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-79 6.4 Medium 2026-06-27
CVE-2026-11987 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-639 4.3 Medium 2026-06-27
CVE-2026-10023 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-639 4.3 Medium 2026-06-18
CVE-2026-3504 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API Endpoint — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-200 5.3 Medium 2026-05-02
CVE-2025-14977 Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-284 8.1 High 2026-01-20
CVE-2020-36748 Dokan <= 3.0.8 - Cross-Site Request Forgery Bypass — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-352 4.3 Medium 2023-07-01

This page lists every published CVE security advisory associated with dokaninc. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.