VYPR

Dedecms

by Dedecms

Source repositories

CVEs (173)

  • CVE-2023-40874MedAug 24, 2023
    risk 0.35cvss 5.4epss 0.00

    DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters.

  • CVE-2023-31757MedMay 19, 2023
    risk 0.35cvss 5.4epss 0.00

    DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'

  • CVE-2022-48140MedFeb 2, 2023
    risk 0.35cvss 5.4epss 0.00

    DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view.php?fmdo=edit&filename.

  • CVE-2020-36493MedOct 22, 2021
    risk 0.35cvss 5.4epss 0.01

    DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

  • CVE-2020-36492MedOct 22, 2021
    risk 0.35cvss 5.4epss 0.01

    DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

  • CVE-2020-36491MedOct 22, 2021
    risk 0.35cvss 5.4epss 0.01

    DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

  • CVE-2020-36490MedOct 22, 2021
    risk 0.35cvss 5.4epss 0.01

    DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

  • CVE-2020-23044MedOct 22, 2021
    risk 0.35cvss 5.4epss 0.01

    DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

  • CVE-2020-16632MedMay 15, 2021
    risk 0.35cvss 5.4epss 0.01

    A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.

  • CVE-2018-6881MedFeb 12, 2018
    risk 0.35cvss 5.3epss 0.02

    EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.

  • CVE-2024-29660MedApr 25, 2024
    risk 0.34cvss 5.3epss 0.00

    Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local attacker to execute arbitrary code via a crafted payload to the stepselect_main.php component.

  • CVE-2026-19353MedAug 9, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is…

  • CVE-2024-9076MedSep 22, 2024
    risk 0.32cvss 4.7epss 0.21

    A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-6335MedJun 20, 2025
    risk 0.31cvss 4.7epss 0.07

    A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing of the file /include/dedetag.class.php of the component Template Handler. The manipulation of the argument notes leads to command injection. The attack may be…

  • CVE-2025-5137MedMay 25, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an unknown function of the file dede/sys_verifies.php?action=getfiles of the component Incomplete Fix CVE-2018-9175. The manipulation of the argument refiles leads to code injection. It…

  • CVE-2024-6940MedJul 21, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2023-7212MedJan 7, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component Backend. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2023-5301MedSep 30, 2023
    risk 0.31cvss 4.7epss 0.06

    A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit…

  • CVE-2024-33401MedApr 29, 2024
    risk 0.29cvss 4.4epss 0.00

    Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum parameter.

  • CVE-2024-4790MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in DedeCMS 5.7.114. This affects an unknown part of the file /sys_verifies.php?action=view. The manipulation of the argument filename with the input ../../../../../etc/passwd leads to path traversal: '../filedir'. It is…

Page 7 of 9