dedecms
165 tracked vulnerabilities.
CVE-2024-28429
MEDIUM
DedeCMS v5.7 - Cross-Site Request Forgery via archives_do.php
Mar 13, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-22895
HIGH
DedeCMS 5.7.112 - Unrestricted Upload of File with Dangerous Type via module_upload.php
Jan 22, 2024
CVSS 8.8
EPSS 0.00
CVE-2023-52047
HIGH
dedecms v5.7.112 - Cross-Site Request Forgery in File Manager
Feb 28, 2024
CVSS 8.8
EPSS 0.00
CVE-2023-7212
MEDIUM
dedecms < 5.7.112 - Unrestricted File Upload in Backend file_class.php
Jan 07, 2024
CVSS 4.7
EPSS 0.00
CVE-2023-49494
MEDIUM
NUCLEI
dedecms v5.7.111 - Reflected Cross-Site Scripting via select_media_post_wangEditor.php
Dec 11, 2023
CVSS 6.1
EPSS 0.02
CVE-2023-49493
MEDIUM
dedecms v5.7.111 - Reflected Cross-Site Scripting via selectimages.php v Parameter
Dec 07, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-49492
MEDIUM
dedecms v5.7.111 - Reflected Cross-Site Scripting via imgstick Parameter
Dec 07, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-43275
HIGH
DedeCMS v5.7 - Cross-Site Request Forgery via /catalog_add.php
Nov 16, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-48068
MEDIUM
dedecms v6.2 - Cross-Site Scripting via spec_add.php
Nov 13, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-5301
MEDIUM
dedecms 5.7.111 - OS Command Injection via albumUploadFiles Parameter in album_add.php
Sep 30, 2023
CVSS 4.7
EPSS 0.01
CVE-2023-43226
HIGH
dedecms < 5.7.111 - Arbitrary File Upload via Baidu News Module
Sep 28, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-5022
MEDIUM
dedecms < 5.7.100 - Absolute Path Traversal via activepath Parameter
Sep 17, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-40784
CRITICAL
dedecms 5.7.102 - Unrestricted Upload of File with Dangerous Type via module_make.php
Sep 12, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-4747
MEDIUM
DedeCMS 5.7.110 - SQL Injection via tag_alias Parameter in tags.php
Sep 04, 2023
CVSS 6.3
EPSS 0.00
CVE-2023-40877
MEDIUM
dedecms <= 5.7.110 - Cross-Site Scripting via Title Parameter
Aug 24, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-40876
MEDIUM
dedecms <= 5.7.110 - Cross-Site Scripting via Title Parameter
Aug 24, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-40875
MEDIUM
dedecms <= 5.7.110 - Cross-Site Scripting via votename and votenote Parameters
Aug 24, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-40874
MEDIUM
dedecms <= 5.7.110 - Cross-Site Scripting via votename and voteitem1 Parameters
Aug 24, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-36298
HIGH
DedeCMS v5.7.109 - Unrestricted File Upload leading to Remote Code Execution
Aug 03, 2023
CVSS 8.8
EPSS 0.09
CVE-2023-34842
CRITICAL
dedecms <= 5.7.109 - Remote Code Execution via Crafted POST Request to /dede/tpl.php
Jul 31, 2023
CVSS 9.8
EPSS 0.03
CVE-2023-37839
CRITICAL
dedecms v5.7.109 - Arbitrary File Upload via file_manage_control.php
Jul 13, 2023
CVSS 9.8
EPSS 0.01
CVE-2023-3578
MEDIUM
NUCLEI
dedecms 5.7.109 - Server-Side Request Forgery via co_do.php rssurl Parameter
Jul 10, 2023
CVSS 5.5
EPSS 0.81
CVE-2023-2928
MEDIUM
dedecms < 5.7.106 - Remote Code Injection via article_allowurl_edit.php allurls Parameter
May 27, 2023
CVSS 6.3
EPSS 0.66
CVE-2023-31757
MEDIUM
dedecms <= 5.7.108 - Cross-Site Scripting via sys_info.php Parameters
May 19, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-2424
MEDIUM
DedeCMS 5.7.106 - Unrestricted File Upload via UpDateMemberModCache Function
Apr 29, 2023
CVSS 6.3
EPSS 0.01
Products
Quick Filters