dedecms
165 tracked vulnerabilities.
CVE-2023-30380
HIGH
dedecms v5.7.107 - Path Traversal via /dialog/select_media.php
Apr 27, 2023
CVSS 7.5
EPSS 0.01
CVE-2023-27733
HIGH
dedecms v5.7.106 - SQL Injection via sys_sql_query.php
Apr 17, 2023
CVSS 7.2
EPSS 0.00
CVE-2023-2059
MEDIUM
NUCLEI
dedecms 5.7.87 - Path Traversal via select_templets.php
Apr 14, 2023
CVSS 4.3
EPSS 0.06
CVE-2023-2056
MEDIUM
dedecms < 5.7.87 - Remote Code Execution via GetSystemFile Function
Apr 14, 2023
CVSS 6.3
EPSS 0.01
CVE-2023-27709
HIGH
dedecms < 5.7.106 - SQL Injection via rank_* Parameter in /dedestory_catalog.php
Mar 16, 2023
CVSS 7.2
EPSS 0.02
CVE-2023-27707
HIGH
dedecms < 5.7.106 - SQL Injection via rank_* Parameter in group_store.php
Mar 16, 2023
CVSS 7.2
EPSS 0.02
CVE-2022-48140
MEDIUM
dedecms v5.7.97 - Cross-Site Scripting in file_manage_view.php
Feb 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2022-46442
CRITICAL
dedecms <= V5.7.102 - SQL Injection
Dec 27, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-43192
MEDIUM
dedecms v5.7.101 - Arbitrary File Upload via file_manage_control.php
Nov 17, 2022
CVSS 6.7
EPSS 0.00
CVE-2022-43031
HIGH
dedecms v6.1.9 - Cross-Site Request Forgery
Nov 09, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-40921
HIGH
dedecms V5.7.99 - Arbitrary File Upload via file_manage_control.php
Oct 12, 2022
CVSS 7.2
EPSS 0.00
CVE-2022-40886
HIGH
DedeCMS 5.7.98 - File Upload Vulnerability
Oct 03, 2022
CVSS 7.2
EPSS 0.00
CVE-2022-36583
MEDIUM
dedecms V5.7.97 - Cross-Site Scripting via dopost, rpok, and aid Parameters
Sep 01, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-36216
HIGH
dedecms 5.7.94-5.7.97 - Remote Code Execution via member_toadmin.php
Aug 17, 2022
CVSS 7.2
EPSS 0.05
CVE-2022-35516
CRITICAL
dedecms 5.7.93-5.7.96 - Remote Code Execution via login.php
Aug 17, 2022
CVSS 9.8
EPSS 0.13
CVE-2022-34531
CRITICAL
dedecms v5.7.95 - Remote Code Execution via mytag_main.php
Jul 29, 2022
CVSS 9.8
EPSS 0.14
CVE-2022-30508
MEDIUM
dedecms v5.7.93 - Arbitrary File Deletion via upload.php delete parameter
May 26, 2022
CVSS 6.5
EPSS 0.01
CVE-2022-23337
CRITICAL
DedeCMS v5.7.87 - SQL Injection via article_coonepage_rule.php ids Parameter
Feb 14, 2022
CVSS 9.8
EPSS 0.10
CVE-2021-32073
HIGH
DedeCMS V5.7 SP2 - Cross-Site Request Forgery Leading to Remote Code Execution
May 15, 2021
CVSS 8.8
EPSS 0.00
CVE-2020-36497
MEDIUM
dedecms v7.5 SP2 - Cross-Site Scripting via makehtml_homepage.php Parameters
Oct 22, 2021
CVSS 6.1
EPSS 0.00
CVE-2020-36496
MEDIUM
dedecms v7.5 SP2 - Cross-Site Scripting via sys_admin_user_edit.php Parameters
Oct 22, 2021
CVSS 6.1
EPSS 0.00
CVE-2020-36495
MEDIUM
DedeCMS v7.5 SP2 - Cross-Site Scripting via file_manage_view.php Parameters
Oct 22, 2021
CVSS 6.1
EPSS 0.00
CVE-2020-36494
MEDIUM
dedecms v7.5 SP2 - Cross-Site Scripting via mychannel_edit.php Parameters
Oct 22, 2021
CVSS 6.1
EPSS 0.00
CVE-2020-36493
MEDIUM
dedecms v7.5 SP2 - Cross-Site Scripting via media_main.php Parameters
Oct 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36492
MEDIUM
dedecms v7.5 SP2 - Stored Cross-Site Scripting via select_media.php Parameters
Oct 22, 2021
CVSS 5.4
EPSS 0.00
Products
Quick Filters