shouldiuse.io

Categories

VERDICT

dotCMS Review

Depends

Should I use dotCMS?

Headless CMS built for multi-site management, flexible content modeling, and omnichannel delivery at enterprise scale. - dotcms.com

· 13 hours ago

Buy dotCMS if you run many sites and channels with developers on staff. Small teams or simple sites should choose a lighter, cheaper CMS.

Confidence

Medium. Based on 40+ public sources; several review and pricing snippets were truncated, so exact prices could not be verified.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo supporting evidence found
  • Security posture

Pricing

Self-hosted core

Free (Business Source License)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Enterprise / cloudNot publicly listed

Best for

  • Multi-site, multi-channel enterprises
  • Teams with in-house developers
  • Fortune 500-scale content operations
  • Hybrid headless plus visual editing

Not for

  • Small sites, blogs, brochure pages
  • Teams with no developers
  • Buyers wanting transparent self-serve pricing
  • Non-technical marketers needing plug-and-play editing

Gotchas - check before you buy

high

CVE-2026-8054 unauthenticated SQL injection observed exploited; patch immediately

medium

BSL license (Nov 2025) restricts some use versus old open-source terms

medium

No public price list; expect sales negotiation before seeing real numbers

low

Guess: Velocity templating adds a learning curve for modern dev teams

Pros and cons

Pros

  • Strong multi-site management and omnichannel delivery
  • GraphQL and REST APIs for flexible headless frontends
  • Open-source core with public code
  • Won 6+ categories in G2 Grid report
  • Named customers include Telus, White Castle, Jostens

Cons

  • Requires experienced developers; steep for non-technical teams
  • Repeated serious CVEs: unauthenticated SQLi, RCE, path traversal
  • Relicensed from open source to Business Source License
  • Opaque, sales-led pricing across five tiers
  • Comparisons rate Sanity above dotCMS for scaling

Sources & method

- 13 sources - Multiple serious CVEs published 2017–2026 (SQLi, RCE, sandbox escape); vendor maintains a trust center and advisories.

official x3review x7security x2news x1
  • CVE-2026-8054 — unauthenticated SQL injection, Unauthenticated SQL injection in dotCMS Core; exploitation observed in the wild.
  • CVE-2025-8311 — blind SQL injection, Boolean-based blind SQL injection vulnerability.
  • CVE-2022-45783 — path traversal, Improper limitation of a pathname to a restricted directory.
  • 2022 critical RCE and Fortinet-found flaws, Critical remote code execution disclosed; FortiGuard Labs found multiple vulnerabilities the same year.

Key stats

  • Value for money: 3/5

    Rating

  • Free (Business Source License)

    Starting price

  • 13

    Sources

  • Analyzed

  • Value for money: 3/5. Five tiers, sales-led, no public prices
  • Ease of use: 3/5. Guess: comparisons say it requires developer expertise
  • Feature depth: 4/5. Multi-site, omnichannel, GraphQL, AI features
  • Support quality. No supporting evidence found
  • Security posture: 2/5. Repeated SQLi/RCE CVEs; advisories published
  • 3.6/5 Review rating 185 reviews on RFP.wiki
  • 5 Pricing tiers listed on G2
  • Yes Free self-hosting open-source core, now BSL-licensed
  • 6+ Public CVEs since 2017 incl. SQLi, RCE, path traversal

Pricing

Self-hosted core

Free (Business Source License)

  • Full source on GitHub
  • Check BSL usage limits

Enterprise / cloud

Not publicly listed

  • Five tiers per G2
  • Sales-led contracts

Security

Multiple serious CVEs published 2017–2026 (SQLi, RCE, sandbox escape); vendor maintains a trust center and advisories.

  • CVE-2026-8054 — unauthenticated SQL injectionUnauthenticated SQL injection in dotCMS Core; exploitation observed in the wild.⁹
  • CVE-2025-8311 — blind SQL injectionBoolean-based blind SQL injection vulnerability.
  • CVE-2022-45783 — path traversalImproper limitation of a pathname to a restricted directory.
  • 2022 critical RCE and Fortinet-found flawsCritical remote code execution disclosed; FortiGuard Labs found multiple vulnerabilities the same year.10

What users say

Reviews on G2, Capterra and aggregators are broadly positive (roughly 3.6–4.1/5) but repeatedly note developer expertise is required.

“Superb And Solid CMS”
Findstack user review

Alternatives

Compare dotCMS with each alternative.

  • Sanity

    Headless rival rated stronger for rapid scaling

  • Contentful

    Polished API-first headless CMS for bigger budgets

  • Strapi

    Open-source headless option for leaner dev teams

    dotCMS vs Strapi

Companies that use it

  • Telus13
  • White Castle
  • Jostens
  • Worldline
  • Southern Phone
Full analysis

Based on 40+ public sources; several review and pricing snippets were truncated, so exact prices could not be verified.

Enterprise headless CMS for multi-site orgs with developers. Overkill for small teams; notable CVE history.

Methodology

Based on 40+ public sources; several review and pricing snippets were truncated, so exact prices could not be verified.

Read how a report is made.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. review
  7. review
  8. news
  9. security
  10. security
  11. official
  12. official
  13. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.