Docebo
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Docebo product.
RSS Feeds for Docebo security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Docebo products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Docebo Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 1 vulnerability in Docebo with an average score of 8.2 out of ten. Docebo did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 8.20 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 2 | 9.30 |
It may take a day or so for new Docebo vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Docebo Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2018-25170 | Mar 06, 2026 |
DoceboLMS 1.2 SQLi via lesson.php (id,idC,idU) - UnauthDoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id, idC, and idU parameters. Attackers can send GET requests to the lesson.php endpoint with malicious SQL payloads to extract sensitive database information. |
|
| CVE-2022-31362 | Jun 23, 2022 |
Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerabilityDocebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer |
|
| CVE-2022-31361 | Jun 23, 2022 |
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerabilityDocebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer |
|