dedecms records
166 published records for vendor dedecms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 22
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)48
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')44
- CWE-434 Unrestricted Upload of File with Dangerous Type21
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')14
- CWE-94 Improper Control of Generation of Code ('Code Injection')12
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
166 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2018-7700Proof of concept | DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specifydedecms · dedecms · CWE-352 | High8.8 | — | 74.1% | Mar 27, 2018 |
52Plan | CVE-2015-4553Proof of concept | A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.dedecms · dedecms · CWE-434 | High8.8 | — | 56.7% | Jan 6, 2020 |
50Plan | CVE-2023-2928Proof of concept | DedeCMS article_allowurl_edit.php code injectiondedecms · dedecms · CWE-94 | High8.8 | — | 51.4% | May 27, 2023 |
46Plan | CVE-2022-34531No exploit | DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.dedecms · dedecms | Critical9.8 | — | 24.7% | Jul 29, 2022 |
43Plan | CVE-2017-17731Proof of concept | DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.dedecms · dedecms · CWE-89 | Critical9.8 | — | 13.2% | Dec 18, 2017 |
40Plan | CVE-2023-3578Proof of concept | DedeCMS co_do.php server-side request forgerydedecms · dedecms · CWE-918 | Critical9.8 | — | 3.6% | Jul 10, 2023 |
40Plan | CVE-2022-35516No exploit | DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.dedecms · dedecms · CWE-94 | Critical9.8 | — | 2.6% | Aug 17, 2022 |
40Plan | CVE-2022-23337No exploit | DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.dedecms · dedecms · CWE-89 | Critical9.8 | — | 2.2% | Feb 14, 2022 |
40Plan | CVE-2018-9175No exploit | DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code dedecms · dedecms · CWE-94 | Critical9.8 | — | 2.2% | Apr 1, 2018 |
40Plan | CVE-2020-18114No exploit | An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM formatdedecms · dedecms · CWE-434 | Critical9.8 | — | 1.9% | Aug 27, 2021 |
40Plan | CVE-2018-19061No exploit | DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.dedecms · dedecms · CWE-89 | Critical9.8 | — | 1.8% | Nov 7, 2018 |
40Plan | CVE-2020-22198No exploit | SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.dedecms · dedecms · CWE-89 | Critical9.8 | — | 1.7% | Jun 16, 2021 |
39Monitor | CVE-2018-9174No exploit | sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents dedecms · dedecms · CWE-94 | Critical9.8 | — | 1.4% | Apr 1, 2018 |
39Monitor | CVE-2018-12045No exploit | DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request witdedecms · dedecms · CWE-434 | Critical9.8 | — | 1.4% | Jun 7, 2018 |
39Monitor | CVE-2018-10375No exploit | A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to uploadedecms · dedecms · CWE-434 | Critical9.8 | — | 1.2% | Apr 25, 2018 |
39Monitor | CVE-2023-37839No exploit | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via udedecms · dedecms · CWE-434 | Critical9.8 | — | 1.2% | Jul 13, 2023 |
39Monitor | CVE-2023-34842No exploit | Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dededecms · dedecms · CWE-94 | Critical9.8 | — | 1.1% | Jul 31, 2023 |
39Monitor | CVE-2017-17730No exploit | DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.dedecms · dedecms · CWE-89 | Critical9.8 | — | 1.1% | Dec 18, 2017 |
39Monitor | CVE-2026-30694No exploit | An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter componentdedecms · dedecms · CWE-94 | Critical9.8 | — | 1.0% | Mar 19, 2026 |
39Monitor | CVE-2023-2056No exploit | DedeCMS module_main.php GetSystemFile code injectiondedecms · dedecms · CWE-94 | Critical9.8 | — | 1.0% | Apr 14, 2023 |
39Monitor | CVE-2026-30643No exploit | An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.dedecms · dedecms · CWE-94 | Critical9.8 | — | 0.8% | Apr 1, 2026 |
39Monitor | CVE-2024-35510No exploit | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via udedecms · dedecms · CWE-434 | Critical9.8 | — | 0.7% | May 28, 2024 |
39Monitor | CVE-2023-40784No exploit | DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.dedecms · dedecms · CWE-434 | Critical9.8 | — | 0.7% | Sep 12, 2023 |
39Monitor | CVE-2023-4747No exploit | DedeCMS tags.php sql injectiondedecms · dedecms · CWE-89 | Critical9.8 | — | 0.7% | Sep 3, 2023 |
39Monitor | CVE-2024-29661No exploit | A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.dedecms · dedecms · CWE-434 | Critical9.8 | — | 0.7% | Apr 22, 2024 |
- CVE-2018-770057Plan
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify
HighCVSS 8.8Proof of conceptEPSS 74%dedecms · dedecmsMar 27, 2018
- CVE-2015-455352Plan
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
HighCVSS 8.8Proof of conceptEPSS 57%dedecms · dedecmsJan 6, 2020
- CVE-2023-292850Plan
DedeCMS article_allowurl_edit.php code injection
HighCVSS 8.8Proof of conceptEPSS 51%dedecms · dedecmsMay 27, 2023
- CVE-2022-3453146Plan
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
CriticalCVSS 9.8No exploitEPSS 25%dedecms · dedecmsJul 29, 2022
- CVE-2017-1773143Plan
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
CriticalCVSS 9.8Proof of conceptEPSS 13%dedecms · dedecmsDec 18, 2017
- CVE-2023-357840Plan
DedeCMS co_do.php server-side request forgery
CriticalCVSS 9.8Proof of conceptEPSS 4%dedecms · dedecmsJul 10, 2023
- CVE-2022-3551640Plan
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
CriticalCVSS 9.8No exploitEPSS 3%dedecms · dedecmsAug 17, 2022
- CVE-2022-2333740Plan
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
CriticalCVSS 9.8No exploitEPSS 2%dedecms · dedecmsFeb 14, 2022
- CVE-2018-917540Plan
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code
CriticalCVSS 9.8No exploitEPSS 2%dedecms · dedecmsApr 1, 2018
- CVE-2020-1811440Plan
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format
CriticalCVSS 9.8No exploitEPSS 2%dedecms · dedecmsAug 27, 2021
- CVE-2018-1906140Plan
DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.
CriticalCVSS 9.8No exploitEPSS 2%dedecms · dedecmsNov 7, 2018
- CVE-2020-2219840Plan
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
CriticalCVSS 9.8No exploitEPSS 2%dedecms · dedecmsJun 16, 2021
- CVE-2018-917439Monitor
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsApr 1, 2018
- CVE-2018-1204539Monitor
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request wit
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsJun 7, 2018
- CVE-2018-1037539Monitor
A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to uploa
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsApr 25, 2018
- CVE-2023-3783939Monitor
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via u
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsJul 13, 2023
- CVE-2023-3484239Monitor
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /de
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsJul 31, 2023
- CVE-2017-1773039Monitor
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsDec 18, 2017
- CVE-2026-3069439Monitor
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsMar 19, 2026
- CVE-2023-205639Monitor
DedeCMS module_main.php GetSystemFile code injection
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsApr 14, 2023
- CVE-2026-3064339Monitor
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsApr 1, 2026
- CVE-2024-3551039Monitor
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via u
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsMay 28, 2024
- CVE-2023-4078439Monitor
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsSep 12, 2023
- CVE-2023-474739Monitor
DedeCMS tags.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsSep 3, 2023
- CVE-2024-2966139Monitor
A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
CriticalCVSS 9.8No exploitEPSS 1%dedecms · dedecmsApr 22, 2024