VYPR

Dedecms

by Dedecms

Source repositories

CVEs (173)

  • CVE-2023-2059MedApr 14, 2023
    risk 0.28cvss 4.3epss 0.02

    A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploads/include/dialog/select_templets.php. The manipulation leads to path traversal: '..\filedir'. The attack may be launched…

  • CVE-2024-12183LowDec 4, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS of the file /plus/carbuyaction.php of the component HTTP POST Request Handler. The manipulation leads to cross site scripting. It is possible to initiate the…

  • CVE-2024-12182LowDec 4, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some unknown functionality of the file /member/soft_add.php. The manipulation of the argument body leads to cross site scripting. The attack may be launched…

  • CVE-2024-12181LowDec 4, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component SWF File Handler. The manipulation of the argument mediatype leads to cross site scripting. The…

  • CVE-2024-12180LowDec 4, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file /member/article_add.php. The manipulation of the argument body leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…

  • CVE-2024-11138LowNov 12, 2024
    risk 0.18cvss 2.7epss 0.02

    A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possible to initiate the attack remotely. The…

  • CVE-2011-5200Sep 23, 2012
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.

  • CVE-2009-3806Oct 27, 2009
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.

  • CVE-2026-15700MedJul 14, 2026
    risk 0.00cvss 4.7epss 0.00

    A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. The manipulation of the argument filename results in path traversal. The attack can be…

  • CVE-2026-15533MedJul 13, 2026
    risk 0.00cvss 4.7epss 0.00

    A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a manipulation of the argument Column Name results in code injection. The attack is possible to be carried out…

  • CVE-2024-30965HigApr 2, 2024
    risk 0.00cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.

  • CVE-2010-1097Mar 24, 2010
    risk 0.00cvss epss 0.01

    include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to…

  • CVE-2009-2270Jul 1, 2009
    risk 0.00cvss epss 0.02

    Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via unspecified vectors, as demonstrated by a .jpg.php…

Page 9 of 9