VYPR

Dedecms

by Dedecms

Source repositories

CVEs (173)

  • CVE-2023-43226HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-36298HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.02

    DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).

  • CVE-2022-43031HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.

  • CVE-2020-18917HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.01

    The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.

  • CVE-2021-32073HigMay 15, 2021
    risk 0.57cvss 8.8epss 0.01

    DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.

  • CVE-2019-8933HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.03

    In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, clicking on Default Template…

  • CVE-2019-6289HigJan 15, 2019
    risk 0.57cvss 8.8epss 0.02

    uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrated by the 1.pHP filename.

  • CVE-2018-16785HigSep 19, 2018
    risk 0.57cvss 8.8epss 0.02

    XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell

  • CVE-2018-9134HigMar 30, 2018
    risk 0.57cvss 8.8epss 0.01

    file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.

  • CVE-2017-17727HigDec 18, 2017
    risk 0.57cvss 8.8epss 0.01

    DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parameter to member/article_edit.php.

  • CVE-2018-6910HigFeb 13, 2018
    risk 0.50cvss 7.5epss 0.19

    DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.

  • CVE-2023-30380HigApr 27, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.

  • CVE-2019-8362HigFeb 16, 2019
    risk 0.49cvss 7.5epss 0.01

    DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input validation only checks that .jpg,…

  • CVE-2018-12046HigJun 8, 2018
    risk 0.49cvss 7.5epss 0.01

    DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.

  • CVE-2026-10608HigJun 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit has been released to the public…

  • CVE-2026-10607HigJun 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and…

  • CVE-2026-10606HigJun 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be launched remotely. The…

  • CVE-2024-42636HigAug 23, 2024
    risk 0.47cvss 7.2epss 0.01

    DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

  • CVE-2023-27733HigApr 17, 2023
    risk 0.47cvss 7.2epss 0.01

    DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php.

  • CVE-2023-27709HigMar 16, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.

Page 3 of 9