Vendor CVEs
Dedecms
All CVEs
176 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34531 | Cri | 0.66 | 9.8 | 0.23 | Jul 29, 2022 | DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php. | ||
| CVE-2015-4553 | Hig | 0.65 | 8.8 | 0.57 | Jan 6, 2020 | A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell. | ||
| CVE-2017-17731 | Cri | 0.65 | 9.8 | 0.13 | Dec 18, 2017 | DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php. | ||
| CVE-2026-38615 | Cri | 0.64 | 9.8 | 0.01 | Jun 9, 2026 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. | ||
| CVE-2026-30643 | Cri | 0.64 | 9.8 | 0.01 | Apr 1, 2026 | An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload. | ||
| CVE-2026-30694 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2026 | An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component | ||
| CVE-2024-35510 | Cri | 0.64 | 9.8 | 0.01 | May 28, 2024 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-35375 | Cri | 0.64 | 9.8 | 0.00 | May 23, 2024 | There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS | ||
| CVE-2024-29661 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2024 | A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload. | ||
| CVE-2024-29684 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code. | ||
| CVE-2023-40784 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. | ||
| CVE-2023-34842 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php. | ||
| CVE-2023-37839 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2022-46442 | Cri | 0.64 | 9.8 | 0.01 | Dec 27, 2022 | dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query. | ||
| CVE-2022-44120 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2022 | dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. | ||
| CVE-2022-44118 | Cri | 0.64 | 9.8 | 0.02 | Nov 23, 2022 | dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php. | ||
| CVE-2022-35516 | Cri | 0.64 | 9.8 | 0.03 | Aug 17, 2022 | DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php. | ||
| CVE-2022-23337 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2022 | DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter. | ||
| CVE-2020-18114 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2021 | An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format. | ||
| CVE-2020-22198 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2021 | SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php. | ||
| CVE-2018-19061 | Cri | 0.64 | 9.8 | 0.02 | Nov 7, 2018 | DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter. | ||
| CVE-2018-12045 | Cri | 0.64 | 9.8 | 0.01 | Jun 8, 2018 | DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file. | ||
| CVE-2018-10375 | Cri | 0.64 | 9.8 | 0.01 | Apr 25, 2018 | A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and execute arbitrary PHP code via the /dede/archives_do.php?dopost=uploadLitpic litpic parameter when "Content-Type: image/jpeg" is… | ||
| CVE-2018-9175 | Cri | 0.64 | 9.8 | 0.02 | Apr 2, 2018 | DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php. | ||
| CVE-2018-9174 | Cri | 0.64 | 9.8 | 0.01 | Apr 2, 2018 | sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control. | ||
| CVE-2017-17730 | Cri | 0.64 | 9.8 | 0.01 | Dec 18, 2017 | DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php. | ||
| CVE-2018-7700 | Hig | 0.63 | 8.8 | 0.75 | Mar 27, 2018 | DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code. | ||
| CVE-2024-33749 | Cri | 0.59 | 9.1 | 0.01 | May 6, 2024 | DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php. | ||
| CVE-2022-43196 | Cri | 0.59 | 9.1 | 0.01 | Nov 23, 2022 | dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php. | ||
| CVE-2018-20129 | Hig | 0.58 | 8.8 | 0.08 | Dec 13, 2018 | An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by… | ||
| CVE-2026-29839 | Hig | 0.57 | 8.8 | 0.00 | Mar 24, 2026 | DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php. | ||
| CVE-2024-30855 | Hig | 0.57 | 8.8 | 0.00 | Dec 29, 2025 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php. | ||
| CVE-2024-46373 | Hig | 0.57 | 8.8 | 0.00 | Sep 18, 2024 | Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend. | ||
| CVE-2024-28673 | Hig | 0.57 | 8.8 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/mychannel_edit.php. | ||
| CVE-2024-28671 | Hig | 0.57 | 8.8 | 0.01 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php. | ||
| CVE-2024-28684 | Hig | 0.57 | 8.8 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/module_main.php | ||
| CVE-2024-28675 | Hig | 0.57 | 8.8 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php | ||
| CVE-2024-28665 | Hig | 0.57 | 8.8 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_add.php | ||
| CVE-2024-28432 | Hig | 0.57 | 8.8 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php. | ||
| CVE-2024-28431 | Hig | 0.57 | 8.8 | 0.00 | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php. | ||
| CVE-2023-52047 | Hig | 0.57 | 8.8 | 0.00 | Feb 28, 2024 | Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager. | ||
| CVE-2024-22895 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2024 | DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php. | ||
| CVE-2023-43275 | Hig | 0.57 | 8.8 | 0.00 | Nov 16, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form. | ||
| CVE-2023-43226 | Hig | 0.57 | 8.8 | 0.01 | Sep 28, 2023 | An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-36298 | Hig | 0.57 | 8.8 | 0.02 | Aug 3, 2023 | DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE). | ||
| CVE-2022-43031 | Hig | 0.57 | 8.8 | 0.01 | Nov 9, 2022 | DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords. | ||
| CVE-2020-18917 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2021 | The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control. | ||
| CVE-2021-32073 | Hig | 0.57 | 8.8 | 0.01 | May 15, 2021 | DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution. | ||
| CVE-2019-8933 | Hig | 0.57 | 8.8 | 0.03 | Feb 19, 2019 | In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, clicking on Default Template… | ||
| CVE-2019-6289 | Hig | 0.57 | 8.8 | 0.02 | Jan 15, 2019 | uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrated by the 1.pHP filename. |
- risk 0.66cvss 9.8epss 0.23
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
- risk 0.65cvss 8.8epss 0.57
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
- risk 0.65cvss 9.8epss 0.13
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
- risk 0.64cvss 9.8epss 0.01
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
- risk 0.64cvss 9.8epss 0.01
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.00
There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS
- risk 0.64cvss 9.8epss 0.01
A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
- risk 0.64cvss 9.8epss 0.01
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.
- risk 0.64cvss 9.8epss 0.01
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
- risk 0.64cvss 9.8epss 0.02
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
- risk 0.64cvss 9.8epss 0.03
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
- risk 0.64cvss 9.8epss 0.02
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
- risk 0.64cvss 9.8epss 0.02
DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.
- risk 0.64cvss 9.8epss 0.01
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.
- risk 0.64cvss 9.8epss 0.01
A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and execute arbitrary PHP code via the /dede/archives_do.php?dopost=uploadLitpic litpic parameter when "Content-Type: image/jpeg" is…
- risk 0.64cvss 9.8epss 0.02
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.
- risk 0.64cvss 9.8epss 0.01
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.
- risk 0.64cvss 9.8epss 0.01
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
- risk 0.63cvss 8.8epss 0.75
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.
- risk 0.59cvss 9.1epss 0.01
DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
- risk 0.59cvss 9.1epss 0.01
dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.
- risk 0.58cvss 8.8epss 0.08
An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by…
- risk 0.57cvss 8.8epss 0.00
DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.
- risk 0.57cvss 8.8epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.
- risk 0.57cvss 8.8epss 0.00
Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
- risk 0.57cvss 8.8epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/mychannel_edit.php.
- risk 0.57cvss 8.8epss 0.01
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php.
- risk 0.57cvss 8.8epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/module_main.php
- risk 0.57cvss 8.8epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php
- risk 0.57cvss 8.8epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_add.php
- risk 0.57cvss 8.8epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.
- risk 0.57cvss 8.8epss 0.00
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.
- risk 0.57cvss 8.8epss 0.00
Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.
- risk 0.57cvss 8.8epss 0.01
DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.
- risk 0.57cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.57cvss 8.8epss 0.02
DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).
- risk 0.57cvss 8.8epss 0.01
DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.
- risk 0.57cvss 8.8epss 0.01
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
- risk 0.57cvss 8.8epss 0.01
DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.
- risk 0.57cvss 8.8epss 0.03
In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, clicking on Default Template…
- risk 0.57cvss 8.8epss 0.02
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrated by the 1.pHP filename.
Page 1 of 4