CVE-2026-76783
- EPSS 0.25%
- Veröffentlicht 20.08.2026 00:15:35
- Zuletzt bearbeitet 20.08.2026 18:16:52
A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The expl...
- EPSS 0.24%
- Veröffentlicht 09.08.2026 13:16:51
- Zuletzt bearbeitet 12.08.2026 20:59:21
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed r...
CVE-2026-51077
- EPSS 0.21%
- Veröffentlicht 27.07.2026 00:00:00
- Zuletzt bearbeitet 28.07.2026 16:23:19
SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component
CVE-2026-15700
- EPSS 0.36%
- Veröffentlicht 14.07.2026 16:15:07
- Zuletzt bearbeitet 15.07.2026 14:17:18
A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. The manipulation of the argument filename results in path ...
CVE-2026-15533
- EPSS 0.25%
- Veröffentlicht 13.07.2026 04:45:06
- Zuletzt bearbeitet 13.07.2026 20:16:47
A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a manipulation of the argument Column Name results in code injection. The attack is po...
CVE-2026-38615
- EPSS 0.82%
- Veröffentlicht 09.06.2026 17:17:05
- Zuletzt bearbeitet 23.07.2026 08:10:00
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
CVE-2026-10608
- EPSS 0.31%
- Veröffentlicht 02.06.2026 18:00:10
- Zuletzt bearbeitet 22.07.2026 19:10:00
A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit ha...
CVE-2026-10607
- EPSS 0.31%
- Veröffentlicht 02.06.2026 17:45:05
- Zuletzt bearbeitet 22.07.2026 19:10:00
A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit i...
CVE-2026-10606
- EPSS 0.25%
- Veröffentlicht 02.06.2026 16:30:08
- Zuletzt bearbeitet 22.07.2026 19:10:00
A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be...
CVE-2026-10581
- EPSS 0.2%
- Veröffentlicht 02.06.2026 02:30:08
- Zuletzt bearbeitet 22.07.2026 19:10:00
A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack ...