dedecms

165 tracked vulnerabilities.

CVE-2024-28429 MEDIUM
DedeCMS v5.7 - Cross-Site Request Forgery via archives_do.php
Mar 13, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-22895 HIGH
DedeCMS 5.7.112 - Unrestricted Upload of File with Dangerous Type via module_upload.php
Jan 22, 2024
CVSS 8.8
EPSS 0.00
CVE-2023-52047 HIGH
dedecms v5.7.112 - Cross-Site Request Forgery in File Manager
Feb 28, 2024
CVSS 8.8
EPSS 0.00
CVE-2023-7212 MEDIUM
dedecms < 5.7.112 - Unrestricted File Upload in Backend file_class.php
Jan 07, 2024
CVSS 4.7
EPSS 0.00
CVE-2023-49494 MEDIUM NUCLEI
dedecms v5.7.111 - Reflected Cross-Site Scripting via select_media_post_wangEditor.php
Dec 11, 2023
CVSS 6.1
EPSS 0.02
CVE-2023-49493 MEDIUM
dedecms v5.7.111 - Reflected Cross-Site Scripting via selectimages.php v Parameter
Dec 07, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-49492 MEDIUM
dedecms v5.7.111 - Reflected Cross-Site Scripting via imgstick Parameter
Dec 07, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-43275 HIGH
DedeCMS v5.7 - Cross-Site Request Forgery via /catalog_add.php
Nov 16, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-48068 MEDIUM
dedecms v6.2 - Cross-Site Scripting via spec_add.php
Nov 13, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-5301 MEDIUM
dedecms 5.7.111 - OS Command Injection via albumUploadFiles Parameter in album_add.php
Sep 30, 2023
CVSS 4.7
EPSS 0.01
CVE-2023-43226 HIGH
dedecms < 5.7.111 - Arbitrary File Upload via Baidu News Module
Sep 28, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-5022 MEDIUM
dedecms < 5.7.100 - Absolute Path Traversal via activepath Parameter
Sep 17, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-40784 CRITICAL
dedecms 5.7.102 - Unrestricted Upload of File with Dangerous Type via module_make.php
Sep 12, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-4747 MEDIUM
DedeCMS 5.7.110 - SQL Injection via tag_alias Parameter in tags.php
Sep 04, 2023
CVSS 6.3
EPSS 0.00
CVE-2023-40877 MEDIUM
dedecms <= 5.7.110 - Cross-Site Scripting via Title Parameter
Aug 24, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-40876 MEDIUM
dedecms <= 5.7.110 - Cross-Site Scripting via Title Parameter
Aug 24, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-40875 MEDIUM
dedecms <= 5.7.110 - Cross-Site Scripting via votename and votenote Parameters
Aug 24, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-40874 MEDIUM
dedecms <= 5.7.110 - Cross-Site Scripting via votename and voteitem1 Parameters
Aug 24, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-36298 HIGH
DedeCMS v5.7.109 - Unrestricted File Upload leading to Remote Code Execution
Aug 03, 2023
CVSS 8.8
EPSS 0.09
CVE-2023-34842 CRITICAL
dedecms <= 5.7.109 - Remote Code Execution via Crafted POST Request to /dede/tpl.php
Jul 31, 2023
CVSS 9.8
EPSS 0.03
CVE-2023-37839 CRITICAL
dedecms v5.7.109 - Arbitrary File Upload via file_manage_control.php
Jul 13, 2023
CVSS 9.8
EPSS 0.01
CVE-2023-3578 MEDIUM NUCLEI
dedecms 5.7.109 - Server-Side Request Forgery via co_do.php rssurl Parameter
Jul 10, 2023
CVSS 5.5
EPSS 0.81
CVE-2023-2928 MEDIUM
dedecms < 5.7.106 - Remote Code Injection via article_allowurl_edit.php allurls Parameter
May 27, 2023
CVSS 6.3
EPSS 0.66
CVE-2023-31757 MEDIUM
dedecms <= 5.7.108 - Cross-Site Scripting via sys_info.php Parameters
May 19, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-2424 MEDIUM
DedeCMS 5.7.106 - Unrestricted File Upload via UpDateMemberModCache Function
Apr 29, 2023
CVSS 6.3
EPSS 0.01
Products
dedecms 165