Перейти к содержимому
Noroxi

Записи dedecms

166 опубликованных записей вендора dedecms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
22
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

166 записей
  • CVE-2018-7700
    57В плане

    DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify

    ВысокаяCVSS 8,8Proof of conceptEPSS 74 %

    dedecms · dedecms27 мар. 2018 г.

  • CVE-2015-4553
    52В плане

    A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.

    ВысокаяCVSS 8,8Proof of conceptEPSS 57 %

    dedecms · dedecms6 янв. 2020 г.

  • CVE-2023-2928
    50В плане

    DedeCMS article_allowurl_edit.php code injection

    ВысокаяCVSS 8,8Proof of conceptEPSS 51 %

    dedecms · dedecms27 мая 2023 г.

  • CVE-2022-34531
    46В плане

    DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 25 %

    dedecms · dedecms29 июл. 2022 г.

  • CVE-2017-17731
    43В плане

    DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

    КритическаяCVSS 9,8Proof of conceptEPSS 13 %

    dedecms · dedecms18 дек. 2017 г.

  • CVE-2023-3578
    40В плане

    DedeCMS co_do.php server-side request forgery

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    dedecms · dedecms10 июл. 2023 г.

  • CVE-2022-35516
    40В плане

    DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    dedecms · dedecms17 авг. 2022 г.

  • CVE-2022-23337
    40В плане

    DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dedecms · dedecms14 февр. 2022 г.

  • CVE-2018-9175
    40В плане

    DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dedecms · dedecms1 апр. 2018 г.

  • CVE-2020-18114
    40В плане

    An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dedecms · dedecms27 авг. 2021 г.

  • CVE-2018-19061
    40В плане

    DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dedecms · dedecms7 нояб. 2018 г.

  • CVE-2020-22198
    40В плане

    SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dedecms · dedecms16 июн. 2021 г.

  • CVE-2018-9174
    39Наблюдать

    sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms1 апр. 2018 г.

  • CVE-2018-12045
    39Наблюдать

    DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request wit

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms7 июн. 2018 г.

  • CVE-2018-10375
    39Наблюдать

    A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to uploa

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms25 апр. 2018 г.

  • CVE-2023-37839
    39Наблюдать

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via u

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms13 июл. 2023 г.

  • CVE-2023-34842
    39Наблюдать

    Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /de

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms31 июл. 2023 г.

  • CVE-2017-17730
    39Наблюдать

    DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms18 дек. 2017 г.

  • CVE-2026-30694
    39Наблюдать

    An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms19 мар. 2026 г.

  • CVE-2023-2056
    39Наблюдать

    DedeCMS module_main.php GetSystemFile code injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms14 апр. 2023 г.

  • CVE-2026-30643
    39Наблюдать

    An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms1 апр. 2026 г.

  • CVE-2024-35510
    39Наблюдать

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via u

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms28 мая 2024 г.

  • CVE-2023-40784
    39Наблюдать

    DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms12 сент. 2023 г.

  • CVE-2023-4747
    39Наблюдать

    DedeCMS tags.php sql injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms3 сент. 2023 г.

  • CVE-2024-29661
    39Наблюдать

    A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dedecms · dedecms22 апр. 2024 г.