dedecms

165 tracked vulnerabilities.

CVE-2018-10375 CRITICAL
DedeCMS V5.7 SP2 - Unrestricted File Upload via archives_do.php litpic Parameter
Apr 25, 2018
CVSS 9.8
EPSS 0.01
CVE-2018-9175 CRITICAL
DedeCMS 5.7 - Remote Code Execution via egroup Parameter
Apr 02, 2018
CVSS 9.8
EPSS 0.02
CVE-2018-9174 CRITICAL
DedeCMS 5.7 - Remote Code Execution via sys_verifies.php refiles Parameter
Apr 02, 2018
CVSS 9.8
EPSS 0.01
CVE-2018-9134 HIGH
DedeCMS 5.7 - Cross-Site Request Forgery via File Rename Action
Mar 30, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-7700 HIGH NUCLEI
dedecms 5.7 - Cross-Site Request Forgery to Remote Code Execution via partcode Parameter
Mar 27, 2018
CVSS 8.8
EPSS 0.93
CVE-2018-6910 HIGH NUCLEI
DedeCMS 5.7 - Full Path Disclosure via Direct Request
Feb 13, 2018
CVSS 7.5
EPSS 0.91
CVE-2018-6881 MEDIUM
Dedecms - Information Disclosure
Feb 12, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-17731 CRITICAL NUCLEI
DedeCMS 5.7 - SQL Injection
Dec 18, 2017
CVSS 9.8
EPSS 0.90
CVE-2017-17730 CRITICAL
dedecms < 5.7 - SQL Injection via Logo Parameter
Dec 18, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-17727 HIGH
DedeCMS < 5.6 - Unauthenticated Arbitrary File Upload RCE via member/article_edit.php
Dec 18, 2017
CVSS 8.8
EPSS 0.01
CVE-2015-4553 HIGH
dedecms < 5.7-sp1 - Unrestricted File Upload
Jan 06, 2020
CVSS 8.8
EPSS 0.39
CVE-2011-5200
DeDeCMS - SQL Injection via id Parameter
Sep 23, 2012
EPSS 0.00
CVE-2010-1097
DeDeCMS 5.5 GBK - Authentication Bypass via _SESSION[dede_admin_id] Parameter
Mar 24, 2010
EPSS 0.00
CVE-2009-3806
dedecms 5.1 - SQL Injection via feedback_js.php arcurl Parameter
Oct 27, 2009
EPSS 0.00
CVE-2009-2270
dedecms 5.3 - Unauthenticated Arbitrary File Upload and Remote Code Execution via Double Extension Bypass
Jul 01, 2009
EPSS 0.01
Products
dedecms 165