dedecms

165 tracked vulnerabilities.

CVE-2026-30643 CRITICAL
dedecms < 5.7.118 - Remote Code Execution via Crafted Setup Tag Values
Apr 01, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-29839 HIGH
DedeCMS v5.7.118 - Cross-Site Request Forgery in sys_task_add.php
Mar 24, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-30694 CRITICAL
DedeCMS <=5.7.118 array_filter - Remote Code Execution
Mar 19, 2026
CVSS 9.8
EPSS 0.00
CVE-2025-15004 MEDIUM
dedecms < 5.7.118 - SQL Injection via freelist_main.php orderby Parameter
Dec 22, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-6335 MEDIUM
dedecms < 5.7.2 - Remote Command Injection via Template Handler
Jun 20, 2025
CVSS 4.7
EPSS 0.01
CVE-2025-5137 MEDIUM
DedeCMS 5.7.117 - Remote Code Injection via sys_verifies.php refiles Parameter
May 25, 2025
CVSS 4.7
EPSS 0.00
CVE-2024-30855 HIGH
DedeCMS v5.7 - Cross-Site Request Forgery via makehtml_list_action.php
Dec 29, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-57241 MEDIUM NUCLEI
dedecms 5.71sp1 - URL Redirection via GET Request
Feb 11, 2025
CVSS 6.5
EPSS 0.22
CVE-2024-12183 LOW
dedecms < 5.7.116 - Cross-Site Scripting via RemoveXSS Function in /plus/carbuyaction.php
Dec 04, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-12182 LOW
dedecms < 5.7.116 - Cross-Site Scripting via /member/soft_add.php body Parameter
Dec 04, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-12181 LOW
dedecms < 5.7.116 - Cross-Site Scripting via mediatype Parameter in SWF File Handler
Dec 04, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-12180 LOW
dedecms < 5.7.116 - Cross-Site Scripting via article_add.php body Parameter
Dec 04, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-11138 LOW
DedeCMS 5.7.116 - Unrestricted File Upload via logoimg Parameter
Nov 12, 2024
CVSS 2.7
EPSS 0.00
CVE-2024-9076 MEDIUM
dedecms < 5.7.115 - OS Command Injection via article_string_mix.php
Sep 22, 2024
CVSS 4.7
EPSS 0.02
CVE-2024-46373 HIGH
dedecms V5.7.115 - Authenticated Arbitrary Code Execution via File Upload
Sep 18, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-46372 MEDIUM
dedecms 5.7.115 - Stored Cross-Site Scripting via Advertisement Code Box
Sep 18, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-42636 HIGH
DedeCMS V5.7.115 - Command Injection
Aug 23, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-6940 MEDIUM
DedeCMS 5.7.114 - Remote Code Injection in article_template_rand.php
Jul 21, 2024
CVSS 4.7
EPSS 0.00
CVE-2024-35510 CRITICAL
dedecms v5.7.114 - Arbitrary File Upload via file_manage_control.php
May 28, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-35375 CRITICAL
dedecms 5.7.114 - Unauthenticated Arbitrary File Upload via Media Add Page
May 23, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-34959 MEDIUM
dedecms V5.7.113 - Cross-Site Scripting via sys_data_replace.php
May 17, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-4790 MEDIUM
DedeCMS 5.7.114 - Path Traversal via sys_verifies.php filename Parameter
May 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-34245 MEDIUM
dedecms v5.7.114 - Authenticated Arbitrary File Read via makehtml_js_action.php
May 14, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-4594 MEDIUM
DedeCMS 5.7 - Cross-Site Request Forgery in sys_safe.php
May 07, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-4593 MEDIUM
DedeCMS 5.7 - Cross-Site Request Forgery in sys_multiserv.php
May 07, 2024
CVSS 4.3
EPSS 0.00
Products
dedecms 165