İçeriğe atla
Noroxi

dedecms kayıtları

dedecms üreticisine ait 166 yayımlanmış kayıt.

Tüm kayıtlar

166 kayıt
  • CVE-2018-7700
    57Planlayın

    DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify

    YüksekCVSS 8,8Kavram kanıtıEPSS %74

    dedecms · dedecms27 Mar 2018

  • CVE-2015-4553
    52Planlayın

    A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.

    YüksekCVSS 8,8Kavram kanıtıEPSS %57

    dedecms · dedecms6 Oca 2020

  • CVE-2023-2928
    50Planlayın

    DedeCMS article_allowurl_edit.php code injection

    YüksekCVSS 8,8Kavram kanıtıEPSS %51

    dedecms · dedecms27 May 2023

  • CVE-2022-34531
    46Planlayın

    DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.

    KritikCVSS 9,8İstismar yokEPSS %25

    dedecms · dedecms29 Tem 2022

  • CVE-2017-17731
    43Planlayın

    DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

    KritikCVSS 9,8Kavram kanıtıEPSS %13

    dedecms · dedecms18 Ara 2017

  • CVE-2023-3578
    40Planlayın

    DedeCMS co_do.php server-side request forgery

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    dedecms · dedecms10 Tem 2023

  • CVE-2022-35516
    40Planlayın

    DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.

    KritikCVSS 9,8İstismar yokEPSS %3

    dedecms · dedecms17 Ağu 2022

  • CVE-2022-23337
    40Planlayın

    DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.

    KritikCVSS 9,8İstismar yokEPSS %2

    dedecms · dedecms14 Şub 2022

  • CVE-2018-9175
    40Planlayın

    DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code

    KritikCVSS 9,8İstismar yokEPSS %2

    dedecms · dedecms1 Nis 2018

  • CVE-2020-18114
    40Planlayın

    An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format

    KritikCVSS 9,8İstismar yokEPSS %2

    dedecms · dedecms27 Ağu 2021

  • CVE-2018-19061
    40Planlayın

    DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.

    KritikCVSS 9,8İstismar yokEPSS %2

    dedecms · dedecms7 Kas 2018

  • CVE-2020-22198
    40Planlayın

    SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

    KritikCVSS 9,8İstismar yokEPSS %2

    dedecms · dedecms16 Haz 2021

  • CVE-2018-9174
    39İzleyin

    sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms1 Nis 2018

  • CVE-2018-12045
    39İzleyin

    DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request wit

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms7 Haz 2018

  • CVE-2018-10375
    39İzleyin

    A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to uploa

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms25 Nis 2018

  • CVE-2023-37839
    39İzleyin

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via u

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms13 Tem 2023

  • CVE-2023-34842
    39İzleyin

    Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /de

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms31 Tem 2023

  • CVE-2017-17730
    39İzleyin

    DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms18 Ara 2017

  • CVE-2026-30694
    39İzleyin

    An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms19 Mar 2026

  • CVE-2023-2056
    39İzleyin

    DedeCMS module_main.php GetSystemFile code injection

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms14 Nis 2023

  • CVE-2026-30643
    39İzleyin

    An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms1 Nis 2026

  • CVE-2024-35510
    39İzleyin

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via u

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms28 May 2024

  • CVE-2023-40784
    39İzleyin

    DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms12 Eyl 2023

  • CVE-2023-4747
    39İzleyin

    DedeCMS tags.php sql injection

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms3 Eyl 2023

  • CVE-2024-29661
    39İzleyin

    A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.

    KritikCVSS 9,8İstismar yokEPSS %1

    dedecms · dedecms22 Nis 2024