VYPR

Vendor CVEs

Dedecms

All CVEs

176 total · sorted by risk
  • CVE-2022-34531CriJul 29, 2022
    risk 0.66cvss 9.8epss 0.23

    DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.

  • CVE-2015-4553HigJan 6, 2020
    risk 0.65cvss 8.8epss 0.57

    A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.

  • CVE-2017-17731CriDec 18, 2017
    risk 0.65cvss 9.8epss 0.13

    DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

  • CVE-2026-38615CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.01

    DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

  • CVE-2026-30643CriApr 1, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

  • CVE-2026-30694CriMar 19, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

  • CVE-2024-35510CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-35375CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.00

    There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS

  • CVE-2024-29661CriApr 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.

  • CVE-2024-29684CriMar 26, 2024
    risk 0.64cvss 9.8epss 0.01

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.

  • CVE-2023-40784CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

  • CVE-2023-34842CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.

  • CVE-2023-37839CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2022-46442CriDec 27, 2022
    risk 0.64cvss 9.8epss 0.01

    dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.

  • CVE-2022-44120CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.

  • CVE-2022-44118CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.

  • CVE-2022-35516CriAug 17, 2022
    risk 0.64cvss 9.8epss 0.03

    DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.

  • CVE-2022-23337CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.

  • CVE-2020-18114CriAug 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.

  • CVE-2020-22198CriJun 16, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

  • CVE-2018-19061CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.

  • CVE-2018-12045CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.01

    DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.

  • CVE-2018-10375CriApr 25, 2018
    risk 0.64cvss 9.8epss 0.01

    A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and execute arbitrary PHP code via the /dede/archives_do.php?dopost=uploadLitpic litpic parameter when "Content-Type: image/jpeg" is…

  • CVE-2018-9175CriApr 2, 2018
    risk 0.64cvss 9.8epss 0.02

    DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.

  • CVE-2018-9174CriApr 2, 2018
    risk 0.64cvss 9.8epss 0.01

    sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.

  • CVE-2017-17730CriDec 18, 2017
    risk 0.64cvss 9.8epss 0.01

    DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.

  • CVE-2018-7700HigMar 27, 2018
    risk 0.63cvss 8.8epss 0.75

    DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

  • CVE-2024-33749CriMay 6, 2024
    risk 0.59cvss 9.1epss 0.01

    DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.

  • CVE-2022-43196CriNov 23, 2022
    risk 0.59cvss 9.1epss 0.01

    dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.

  • CVE-2018-20129HigDec 13, 2018
    risk 0.58cvss 8.8epss 0.08

    An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by…

  • CVE-2026-29839HigMar 24, 2026
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.

  • CVE-2024-30855HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.

  • CVE-2024-46373HigSep 18, 2024
    risk 0.57cvss 8.8epss 0.00

    Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.

  • CVE-2024-28673HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/mychannel_edit.php.

  • CVE-2024-28671HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.01

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php.

  • CVE-2024-28684HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/module_main.php

  • CVE-2024-28675HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php

  • CVE-2024-28665HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_add.php

  • CVE-2024-28432HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.

  • CVE-2024-28431HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.

  • CVE-2023-52047HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.00

    Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.

  • CVE-2024-22895HigJan 22, 2024
    risk 0.57cvss 8.8epss 0.01

    DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.

  • CVE-2023-43275HigNov 16, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.

  • CVE-2023-43226HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-36298HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.02

    DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).

  • CVE-2022-43031HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.

  • CVE-2020-18917HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.01

    The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.

  • CVE-2021-32073HigMay 15, 2021
    risk 0.57cvss 8.8epss 0.01

    DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.

  • CVE-2019-8933HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.03

    In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, clicking on Default Template…

  • CVE-2019-6289HigJan 15, 2019
    risk 0.57cvss 8.8epss 0.02

    uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrated by the 1.pHP filename.

Page 1 of 4