VYPR

Vendor CVEs

Dedecms

All CVEs

176 total · sorted by risk
  • CVE-2018-16785HigSep 19, 2018
    risk 0.57cvss 8.8epss 0.02

    XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell

  • CVE-2018-9134HigMar 30, 2018
    risk 0.57cvss 8.8epss 0.01

    file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.

  • CVE-2017-17727HigDec 18, 2017
    risk 0.57cvss 8.8epss 0.01

    DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parameter to member/article_edit.php.

  • CVE-2018-6910HigFeb 13, 2018
    risk 0.50cvss 7.5epss 0.19

    DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.

  • CVE-2023-30380HigApr 27, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.

  • CVE-2019-8362HigFeb 16, 2019
    risk 0.49cvss 7.5epss 0.01

    DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input validation only checks that .jpg,…

  • CVE-2018-12046HigJun 8, 2018
    risk 0.49cvss 7.5epss 0.01

    DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.

  • CVE-2026-10608HigJun 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit has been released to the public…

  • CVE-2026-10607HigJun 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and…

  • CVE-2026-10606HigJun 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be launched remotely. The…

  • CVE-2024-42636HigAug 23, 2024
    risk 0.47cvss 7.2epss 0.01

    DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

  • CVE-2023-27733HigApr 17, 2023
    risk 0.47cvss 7.2epss 0.01

    DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php.

  • CVE-2023-27709HigMar 16, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.

  • CVE-2023-27707HigMar 16, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint.

  • CVE-2022-40921HigOct 12, 2022
    risk 0.47cvss 7.2epss 0.01

    DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.

  • CVE-2022-40886HigOct 3, 2022
    risk 0.47cvss 7.2epss 0.01

    DedeCMS 5.7.98 has a file upload vulnerability in the background.

  • CVE-2022-36216HigAug 17, 2022
    risk 0.47cvss 7.2epss 0.02

    DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.

  • CVE-2018-16784HigSep 21, 2018
    risk 0.47cvss 7.2epss 0.02

    DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.

  • CVE-2023-2928MedMay 27, 2023
    risk 0.45cvss 6.3epss 0.51

    A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can…

  • CVE-2022-43192MedNov 17, 2022
    risk 0.44cvss 6.7epss 0.00

    An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is related to an incomplete fix for CVE-2022-40886.

  • CVE-2024-57241MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.

  • CVE-2024-34245MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.

  • CVE-2022-30508MedMay 26, 2022
    risk 0.42cvss 6.5epss 0.01

    DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.

  • CVE-2019-10014MedMar 24, 2019
    risk 0.42cvss 6.5epss 0.01

    In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, because the key parameter is not properly validated.

  • CVE-2026-10581MedJun 2, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has…

  • CVE-2025-15004MedDec 22, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might…

  • CVE-2024-3685MedApr 12, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in DedeCMS 5.7.112-UTF8. Affected is an unknown function of the file stepselect_main.php. The manipulation of the argument ids leads to sql injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2024-3148MedApr 2, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in DedeCMS 5.7.112. This issue affects some unknown processing of the file dede/makehtml_archives_action.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2024-28682MedMar 13, 2024
    risk 0.41cvss 6.3epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/sys_cache_up.php.

  • CVE-2024-28678MedMar 13, 2024
    risk 0.41cvss 6.3epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_description_main.php

  • CVE-2023-4747MedSep 4, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in DedeCMS 5.7.110. This vulnerability affects unknown code of the file /uploads/tags.php. The manipulation of the argument tag_alias leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…

  • CVE-2023-2424MedApr 29, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uploads/dede/config.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been…

  • CVE-2023-2056MedApr 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public…

  • CVE-2024-46372MedSep 18, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.

  • CVE-2024-33371MedApr 30, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component.

  • CVE-2024-28683MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via create file.

  • CVE-2024-28681MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/plus_edit.php.

  • CVE-2024-28680MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_add.php.

  • CVE-2024-28679MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via Photo Collection.

  • CVE-2024-28677MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/article_keywords_main.php.

  • CVE-2024-28676MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via /dede/article_edit.php.

  • CVE-2024-28670MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_main.php.

  • CVE-2024-28668MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychannel_add.php

  • CVE-2024-28667MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php

  • CVE-2024-28430MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.

  • CVE-2023-49494MedDec 11, 2023
    risk 0.40cvss 6.1epss 0.01

    DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.

  • CVE-2023-49493MedDec 7, 2023
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php.

  • CVE-2023-49492MedDec 7, 2023
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.

  • CVE-2022-36583MedSep 1, 2022
    risk 0.40cvss 6.1epss 0.01

    DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters.

  • CVE-2020-36497MedOct 22, 2021
    risk 0.40cvss 6.1epss 0.01

    DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.