VYPR

Dedebiz

by Dedebiz

CVEs (28)

  • CVE-2023-31546CriDec 14, 2023
    risk 0.66cvss 9.6epss 0.49

    Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.

  • CVE-2024-52770CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-43234CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.

  • CVE-2024-52771CriNov 20, 2024
    risk 0.59cvss 9.1epss 0.01

    DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.

  • CVE-2024-52769HigNov 20, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2022-36215HigAug 17, 2022
    risk 0.47cvss 7.2epss 0.02

    DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.

  • CVE-2024-7906MedAug 18, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical was found in DedeBIZ 6.3.0. This vulnerability affects the function get_mime_type of the file /admin/dialog/select_images_post.php of the component Attachment Settings. The manipulation of the argument upload leads to unrestricted upload.…

  • CVE-2024-7905MedAug 18, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in DedeBIZ 6.3.0. This affects the function AdminUpload of the file admin/archives_do.php. The manipulation of the argument litpic leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2024-7904MedAug 18, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in DedeBIZ 6.3.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/file_manage_control.php of the component File Extension Handler. The manipulation of the argument upfile1 leads to unrestricted…

  • CVE-2024-7903MedAug 18, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in DedeBIZ 6.3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/media_add.php of the component File Extension Handler. The manipulation of the argument upfile1 leads to unrestricted…

  • CVE-2023-5268MedSep 29, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in DedeBIZ 6.2 and classified as critical. This issue affects some unknown processing of the file /src/admin/makehtml_taglist_action.php. The manipulation of the argument mktime leads to sql injection. The attack may be initiated remotely. The exploit…

  • CVE-2023-5266MedSep 29, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in DedeBIZ 6.2. This affects an unknown part of the file /src/admin/tags_main.php. The manipulation of the argument ids leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2024-44717MedAug 29, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2024-44716MedAug 29, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-43232MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.

  • CVE-2025-14648MedDec 14, 2025
    risk 0.31cvss 4.7epss 0.07

    A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown functionality of the file /src/admin/catalog_add.php. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-12927MedNov 10, 2025
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archives_add.php. Such manipulation of the argument flags[] leads to sql injection. The attack can be executed remotely. The exploit has been…

  • CVE-2025-12861MedNov 7, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the file /admin/spec_add.php. This manipulation of the argument flags[] causes sql injection. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2025-12860MedNov 7, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. The manipulation of the argument orderby results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

  • CVE-2025-12859MedNov 7, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_edit.php. The manipulation of the argument ids leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the…

Page 1 of 2