Dedecms
by Dedecms
Source repositories
CVEs (173)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-46372 | Med | 0.40 | 6.1 | 0.00 | Sep 18, 2024 | DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module. | ||
| CVE-2024-33371 | Med | 0.40 | 6.1 | 0.00 | Apr 30, 2024 | Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component. | ||
| CVE-2024-28683 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via create file. | ||
| CVE-2024-28681 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/plus_edit.php. | ||
| CVE-2024-28680 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_add.php. | ||
| CVE-2024-28679 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via Photo Collection. | ||
| CVE-2024-28677 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/article_keywords_main.php. | ||
| CVE-2024-28676 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via /dede/article_edit.php. | ||
| CVE-2024-28670 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_main.php. | ||
| CVE-2024-28668 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychannel_add.php | ||
| CVE-2024-28667 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php | ||
| CVE-2024-28430 | Med | 0.40 | 6.1 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php. | ||
| CVE-2023-49494 | Med | 0.40 | 6.1 | 0.01 | Dec 11, 2023 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php. | ||
| CVE-2023-49493 | Med | 0.40 | 6.1 | 0.00 | Dec 7, 2023 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php. | ||
| CVE-2023-49492 | Med | 0.40 | 6.1 | 0.00 | Dec 7, 2023 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php. | ||
| CVE-2022-36583 | Med | 0.40 | 6.1 | 0.01 | Sep 1, 2022 | DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters. | ||
| CVE-2020-36497 | Med | 0.40 | 6.1 | 0.01 | Oct 22, 2021 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters. | ||
| CVE-2020-36496 | Med | 0.40 | 6.1 | 0.01 | Oct 22, 2021 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters. | ||
| CVE-2020-36495 | Med | 0.40 | 6.1 | 0.01 | Oct 22, 2021 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `filename`, `mid`, `userid`, and `templet' parameters. | ||
| CVE-2020-36494 | Med | 0.40 | 6.1 | 0.01 | Oct 22, 2021 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters. |
- risk 0.40cvss 6.1epss 0.00
DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via create file.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/plus_edit.php.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_add.php.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via Photo Collection.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/article_keywords_main.php.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via /dede/article_edit.php.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_main.php.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychannel_add.php
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.
- risk 0.40cvss 6.1epss 0.01
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php.
- risk 0.40cvss 6.1epss 0.00
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.
- risk 0.40cvss 6.1epss 0.01
DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters.
- risk 0.40cvss 6.1epss 0.01
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.
- risk 0.40cvss 6.1epss 0.01
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.
- risk 0.40cvss 6.1epss 0.01
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `filename`, `mid`, `userid`, and `templet' parameters.
- risk 0.40cvss 6.1epss 0.01
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.
Page 5 of 9