CVE-2024-28430
- EPSS 0.09%
- Veröffentlicht 13.03.2024 13:15:47
- Zuletzt bearbeitet 01.04.2025 13:43:05
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.
CVE-2024-28431
- EPSS 0.18%
- Veröffentlicht 13.03.2024 13:15:47
- Zuletzt bearbeitet 01.04.2025 13:43:02
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.
CVE-2024-28432
- EPSS 0.18%
- Veröffentlicht 13.03.2024 13:15:47
- Zuletzt bearbeitet 01.04.2025 13:42:56
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.
CVE-2023-49453
- EPSS 0.57%
- Veröffentlicht 12.03.2024 08:15:45
- Zuletzt bearbeitet 29.09.2025 15:16:04
Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php.
CVE-2024-25327
- EPSS 0.09%
- Veröffentlicht 08.03.2024 00:15:49
- Zuletzt bearbeitet 21.11.2024 09:00:38
Cross Site Scripting (XSS) vulnerability in Justice Systems FullCourt Enterprise v.8.2 allows a remote attacker to execute arbitrary code via the formatCaseNumber parameter of the Citation search function.
CVE-2023-52047
- EPSS 0.23%
- Veröffentlicht 28.02.2024 20:15:41
- Zuletzt bearbeitet 01.04.2025 13:30:28
Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.
CVE-2024-22895
- EPSS 0.18%
- Veröffentlicht 22.01.2024 15:15:09
- Zuletzt bearbeitet 05.06.2025 16:15:26
DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.
CVE-2023-7212
- EPSS 0.04%
- Veröffentlicht 07.01.2024 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:45:31
A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component Backend. The manipulation leads to unrestricted upload. It is possible to launch the attack re...
CVE-2023-49494
- EPSS 2.24%
- Veröffentlicht 11.12.2023 21:15:07
- Zuletzt bearbeitet 21.11.2024 08:33:29
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.
CVE-2023-49492
- EPSS 0.17%
- Veröffentlicht 07.12.2023 16:15:07
- Zuletzt bearbeitet 21.11.2024 08:33:28
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.