VYPR

Dedecms

by Dedecms

Source repositories

CVEs (173)

  • CVE-2022-34531CriJul 29, 2022
    risk 0.66cvss 9.8epss 0.23

    DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.

  • CVE-2015-4553HigJan 6, 2020
    risk 0.65cvss 8.8epss 0.57

    A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.

  • CVE-2017-17731CriDec 18, 2017
    risk 0.65cvss 9.8epss 0.13

    DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

  • CVE-2026-38615CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.01

    DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

  • CVE-2026-30643CriApr 1, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

  • CVE-2026-30694CriMar 19, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

  • CVE-2024-35510CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-35375CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.00

    There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS

  • CVE-2024-29661CriApr 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.

  • CVE-2024-29684CriMar 26, 2024
    risk 0.64cvss 9.8epss 0.01

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.

  • CVE-2023-40784CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

  • CVE-2023-34842CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.

  • CVE-2023-37839CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2022-46442CriDec 27, 2022
    risk 0.64cvss 9.8epss 0.01

    dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.

  • CVE-2022-35516CriAug 17, 2022
    risk 0.64cvss 9.8epss 0.03

    DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.

  • CVE-2022-23337CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.

  • CVE-2020-18114CriAug 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.

  • CVE-2020-22198CriJun 16, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

  • CVE-2018-19061CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.

  • CVE-2018-12045CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.01

    DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.

Page 1 of 9