CVE-2026-38615
- EPSS 0.82%
- Veröffentlicht 09.06.2026 17:17:05
- Zuletzt bearbeitet 10.06.2026 15:16:33
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
CVE-2026-10608
- EPSS 0.31%
- Veröffentlicht 02.06.2026 18:00:10
- Zuletzt bearbeitet 04.06.2026 14:56:49
A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit ha...
CVE-2026-10607
- EPSS 0.31%
- Veröffentlicht 02.06.2026 17:45:05
- Zuletzt bearbeitet 04.06.2026 14:56:49
A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit i...
CVE-2026-10606
- EPSS 0.25%
- Veröffentlicht 02.06.2026 16:30:08
- Zuletzt bearbeitet 02.06.2026 20:16:31
A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be...
CVE-2026-10581
- EPSS 0.2%
- Veröffentlicht 02.06.2026 02:30:08
- Zuletzt bearbeitet 02.06.2026 13:03:31
A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack ...
CVE-2026-30643
- EPSS 0.57%
- Veröffentlicht 01.04.2026 00:00:00
- Zuletzt bearbeitet 06.04.2026 15:29:18
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
CVE-2026-29839
- EPSS 0.14%
- Veröffentlicht 24.03.2026 00:00:00
- Zuletzt bearbeitet 25.03.2026 20:53:05
DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.
CVE-2026-30694
- EPSS 0.68%
- Veröffentlicht 19.03.2026 00:00:00
- Zuletzt bearbeitet 25.03.2026 21:11:32
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component
CVE-2024-30855
- EPSS 0.19%
- Veröffentlicht 29.12.2025 00:00:00
- Zuletzt bearbeitet 02.01.2026 13:43:49
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.
CVE-2025-15004
- EPSS 0.3%
- Veröffentlicht 22.12.2025 00:02:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads to sql injection. It is possible to initiate the attack remotely. The exploit is ...