dedecms

165 tracked vulnerabilities.

CVE-2020-36491 MEDIUM
dedecms v7.5 SP2 - Cross-Site Scripting via tags_main.php Parameters
Oct 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36490 MEDIUM
DedeCMS v7.5 SP2 - Stored Cross-Site Scripting via file_manage_view.php Parameters
Oct 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-23046 MEDIUM
dedecms v7.5 SP2 - Stored Cross-Site Scripting via tpl.php Parameters
Oct 22, 2021
CVSS 6.1
EPSS 0.00
CVE-2020-23044 MEDIUM
DedeCMS v7.5 SP2 - Cross-Site Scripting via Multiple Parameters in file_pic_view.php
Oct 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-18114 CRITICAL
DedeCMS V5.7SP2 - Arbitrary File Upload via /uploads/dede Component
Aug 27, 2021
CVSS 9.8
EPSS 0.01
CVE-2020-18917 HIGH
dedecms 5.7 SP2 - Remote Code Execution via typename Parameter
Aug 24, 2021
CVSS 8.8
EPSS 0.00
CVE-2020-22198 CRITICAL
dedecms 5.7 - SQL Injection via mdescription Parameter
Jun 16, 2021
CVSS 9.8
EPSS 0.01
CVE-2020-16632 MEDIUM
dedecms V5.7 SP2 - Authenticated Stored Cross-Site Scripting via keyword Parameter
May 15, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-27533 MEDIUM
DedeCMS 5.8 - Cross-Site Scripting in Search Feature
Oct 22, 2020
CVSS 5.4
EPSS 0.01
CVE-2019-10014 MEDIUM
DedeCMS 5.7SP2 - Authenticated Arbitrary Password Reset via ID Parameter
Mar 24, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-8933 HIGH
DedeCMS 5.7SP2 - Unauthenticated Arbitrary File Upload via Template Management
Feb 19, 2019
CVSS 8.8
EPSS 0.24
CVE-2019-8362 HIGH
DedeCMS <= V5.7SP2 - Arbitrary File Upload via album_edit.php ZIP Archive
Feb 16, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6289 HIGH
DedeCMS V57_UTF8_SP2 - Remote Code Execution via Mixed-Case PHP Extension Bypass
Jan 15, 2019
CVSS 8.8
EPSS 0.01
CVE-2018-20129 HIGH
DedeCMS V5.7 SP2 - Remote Code Execution via Double Extension and Content Type Spoofing
Dec 13, 2018
CVSS 8.8
EPSS 0.70
CVE-2018-19061 CRITICAL
DedeCMS 5.7 SP2 - SQL Injection via co_do.php ids Parameter
Nov 07, 2018
CVSS 9.8
EPSS 0.00
CVE-2018-18782 MEDIUM
dedecms 5.7 SP2 - Reflected Cross-Site Scripting via myfriend.php ftype Parameter
Oct 29, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-18781 MEDIUM
DedeCMS 5.7 SP2 - Cross-Site Scripting via Uploads Select Page Parameter
Oct 29, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-18608 MEDIUM NUCLEI
dedecms 5.7 SP2 - Cross-Site Scripting via GetPageList Function
Oct 23, 2018
CVSS 6.1
EPSS 0.08
CVE-2018-18579 MEDIUM
dedecms 5.7 SP2 - Reflected Cross-Site Scripting via PM Folder Parameter
Oct 22, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-18578 MEDIUM
dedecms 5.7 SP2 - Cross-Site Scripting via QR Code Type Parameter
Oct 22, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-16786 MEDIUM
DedeCMS 5.7 SP2 - Stored Cross-Site Scripting via Feedback AJAX Msg Parameter
Sep 21, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-16784 HIGH
DedeCMS 5.7 SP2 - Remote Code Execution via XML Injection
Sep 21, 2018
CVSS 7.2
EPSS 0.03
CVE-2018-16785 HIGH
dedecms V5.7 SP2 - XML Injection
Sep 19, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-12046 HIGH
DedeCMS <= 5.7SP2 - Arbitrary File Write via file_manage_control.php
Jun 08, 2018
CVSS 7.5
EPSS 0.00
CVE-2018-12045 CRITICAL
dedecms <= V5.7SP2 - Arbitrary File Upload via upfile1 Parameter
Jun 08, 2018
CVSS 9.8
EPSS 0.01
Products
dedecms 165