VYPR

Dedecms

by Dedecms

Source repositories

CVEs (173)

  • CVE-2020-23046MedOct 22, 2021
    risk 0.40cvss 6.1epss 0.01

    DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `userid`, and `templet' parameters.

  • CVE-2018-18782MedOct 29, 2018
    risk 0.40cvss 6.1epss 0.01

    Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.

  • CVE-2018-18781MedOct 29, 2018
    risk 0.40cvss 6.1epss 0.01

    DedeCMS 5.7 SP2 allows XSS via the /member/uploads_select.php f or keyword parameter.

  • CVE-2018-18608MedOct 23, 2018
    risk 0.40cvss 6.1epss 0.03

    DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php,…

  • CVE-2018-18579MedOct 22, 2018
    risk 0.40cvss 6.1epss 0.01

    Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter.

  • CVE-2018-18578MedOct 22, 2018
    risk 0.40cvss 6.1epss 0.01

    DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter.

  • CVE-2018-16786MedSep 21, 2018
    risk 0.40cvss 6.1epss 0.01

    DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.

  • CVE-2020-27533MedOct 22, 2020
    risk 0.38cvss 5.4epss 0.04

    A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.

  • CVE-2024-34959MedMay 17, 2024
    risk 0.36cvss 5.5epss 0.00

    DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.

  • CVE-2024-30946MedApr 2, 2024
    risk 0.36cvss 5.5epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.

  • CVE-2024-28666MedMar 13, 2024
    risk 0.36cvss 5.5epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/media_add.php

  • CVE-2024-28429MedMar 13, 2024
    risk 0.36cvss 5.5epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php

  • CVE-2023-5022MedSep 17, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The…

  • CVE-2023-3578MedJul 10, 2023
    risk 0.36cvss 5.5epss 0.04

    A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and…

  • CVE-2024-28672MedMar 13, 2024
    risk 0.35cvss 5.4epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/media_edit.php.

  • CVE-2024-28669MedMar 13, 2024
    risk 0.35cvss 5.4epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_edit.php.

  • CVE-2023-48068MedNov 13, 2023
    risk 0.35cvss 5.4epss 0.00

    DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php.

  • CVE-2023-40877MedAug 24, 2023
    risk 0.35cvss 5.4epss 0.00

    DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.

  • CVE-2023-40876MedAug 24, 2023
    risk 0.35cvss 5.4epss 0.00

    DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.

  • CVE-2023-40875MedAug 24, 2023
    risk 0.35cvss 5.4epss 0.00

    DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters.

Page 6 of 9