Dedecms
Products
2- 173 CVEs
- 3 CVEs
Recent CVEs
176| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34531 | Cri | 0.66 | 9.8 | 0.23 | Jul 29, 2022 | DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php. | ||
| CVE-2015-4553 | Hig | 0.65 | 8.8 | 0.57 | Jan 6, 2020 | A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell. | ||
| CVE-2017-17731 | Cri | 0.65 | 9.8 | 0.13 | Dec 18, 2017 | DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php. | ||
| CVE-2026-38615 | Cri | 0.64 | 9.8 | 0.01 | Jun 9, 2026 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. | ||
| CVE-2026-30643 | Cri | 0.64 | 9.8 | 0.01 | Apr 1, 2026 | An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload. | ||
| CVE-2026-30694 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2026 | An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component | ||
| CVE-2024-35510 | Cri | 0.64 | 9.8 | 0.01 | May 28, 2024 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-35375 | Cri | 0.64 | 9.8 | 0.00 | May 23, 2024 | There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS | ||
| CVE-2024-29661 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2024 | A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload. | ||
| CVE-2024-29684 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code. | ||
| CVE-2023-40784 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. | ||
| CVE-2023-34842 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php. | ||
| CVE-2023-37839 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2022-46442 | Cri | 0.64 | 9.8 | 0.01 | Dec 27, 2022 | dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query. | ||
| CVE-2022-44120 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2022 | dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. | ||
| CVE-2022-44118 | Cri | 0.64 | 9.8 | 0.02 | Nov 23, 2022 | dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php. | ||
| CVE-2022-35516 | Cri | 0.64 | 9.8 | 0.02 | Aug 17, 2022 | DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php. | ||
| CVE-2022-23337 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2022 | DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter. | ||
| CVE-2020-18114 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2021 | An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format. | ||
| CVE-2020-22198 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2021 | SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php. |
- risk 0.66cvss 9.8epss 0.23
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
- risk 0.65cvss 8.8epss 0.57
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
- risk 0.65cvss 9.8epss 0.13
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
- risk 0.64cvss 9.8epss 0.01
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
- risk 0.64cvss 9.8epss 0.01
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.00
There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS
- risk 0.64cvss 9.8epss 0.01
A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
- risk 0.64cvss 9.8epss 0.01
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.
- risk 0.64cvss 9.8epss 0.01
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
- risk 0.64cvss 9.8epss 0.02
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
- risk 0.64cvss 9.8epss 0.02
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
- risk 0.64cvss 9.8epss 0.02
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.