dedecms kayıtları
dedecms üreticisine ait 166 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 22
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)48
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')44
- CWE-434 Unrestricted Upload of File with Dangerous Type21
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')14
- CWE-94 Improper Control of Generation of Code ('Code Injection')12
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
166 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2018-7700Kavram kanıtı | DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specifydedecms · dedecms · CWE-352 | Yüksek8,8 | — | %74,1 | 27 Mar 2018 |
52Planlayın | CVE-2015-4553Kavram kanıtı | A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.dedecms · dedecms · CWE-434 | Yüksek8,8 | — | %56,7 | 6 Oca 2020 |
50Planlayın | CVE-2023-2928Kavram kanıtı | DedeCMS article_allowurl_edit.php code injectiondedecms · dedecms · CWE-94 | Yüksek8,8 | — | %51,4 | 27 May 2023 |
46Planlayın | CVE-2022-34531İstismar yok | DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.dedecms · dedecms | Kritik9,8 | — | %24,7 | 29 Tem 2022 |
43Planlayın | CVE-2017-17731Kavram kanıtı | DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.dedecms · dedecms · CWE-89 | Kritik9,8 | — | %13,2 | 18 Ara 2017 |
40Planlayın | CVE-2023-3578Kavram kanıtı | DedeCMS co_do.php server-side request forgerydedecms · dedecms · CWE-918 | Kritik9,8 | — | %3,6 | 10 Tem 2023 |
40Planlayın | CVE-2022-35516İstismar yok | DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.dedecms · dedecms · CWE-94 | Kritik9,8 | — | %2,6 | 17 Ağu 2022 |
40Planlayın | CVE-2022-23337İstismar yok | DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.dedecms · dedecms · CWE-89 | Kritik9,8 | — | %2,2 | 14 Şub 2022 |
40Planlayın | CVE-2018-9175İstismar yok | DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code dedecms · dedecms · CWE-94 | Kritik9,8 | — | %2,2 | 1 Nis 2018 |
40Planlayın | CVE-2020-18114İstismar yok | An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM formatdedecms · dedecms · CWE-434 | Kritik9,8 | — | %1,9 | 27 Ağu 2021 |
40Planlayın | CVE-2018-19061İstismar yok | DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.dedecms · dedecms · CWE-89 | Kritik9,8 | — | %1,8 | 7 Kas 2018 |
40Planlayın | CVE-2020-22198İstismar yok | SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.dedecms · dedecms · CWE-89 | Kritik9,8 | — | %1,7 | 16 Haz 2021 |
39İzleyin | CVE-2018-9174İstismar yok | sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents dedecms · dedecms · CWE-94 | Kritik9,8 | — | %1,4 | 1 Nis 2018 |
39İzleyin | CVE-2018-12045İstismar yok | DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request witdedecms · dedecms · CWE-434 | Kritik9,8 | — | %1,4 | 7 Haz 2018 |
39İzleyin | CVE-2018-10375İstismar yok | A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to uploadedecms · dedecms · CWE-434 | Kritik9,8 | — | %1,2 | 25 Nis 2018 |
39İzleyin | CVE-2023-37839İstismar yok | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via udedecms · dedecms · CWE-434 | Kritik9,8 | — | %1,2 | 13 Tem 2023 |
39İzleyin | CVE-2023-34842İstismar yok | Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dededecms · dedecms · CWE-94 | Kritik9,8 | — | %1,1 | 31 Tem 2023 |
39İzleyin | CVE-2017-17730İstismar yok | DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.dedecms · dedecms · CWE-89 | Kritik9,8 | — | %1,1 | 18 Ara 2017 |
39İzleyin | CVE-2026-30694İstismar yok | An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter componentdedecms · dedecms · CWE-94 | Kritik9,8 | — | %1,0 | 19 Mar 2026 |
39İzleyin | CVE-2023-2056İstismar yok | DedeCMS module_main.php GetSystemFile code injectiondedecms · dedecms · CWE-94 | Kritik9,8 | — | %1,0 | 14 Nis 2023 |
39İzleyin | CVE-2026-30643İstismar yok | An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.dedecms · dedecms · CWE-94 | Kritik9,8 | — | %0,8 | 1 Nis 2026 |
39İzleyin | CVE-2024-35510İstismar yok | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via udedecms · dedecms · CWE-434 | Kritik9,8 | — | %0,7 | 28 May 2024 |
39İzleyin | CVE-2023-40784İstismar yok | DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.dedecms · dedecms · CWE-434 | Kritik9,8 | — | %0,7 | 12 Eyl 2023 |
39İzleyin | CVE-2023-4747İstismar yok | DedeCMS tags.php sql injectiondedecms · dedecms · CWE-89 | Kritik9,8 | — | %0,7 | 3 Eyl 2023 |
39İzleyin | CVE-2024-29661İstismar yok | A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.dedecms · dedecms · CWE-434 | Kritik9,8 | — | %0,7 | 22 Nis 2024 |
- CVE-2018-770057Planlayın
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify
YüksekCVSS 8,8Kavram kanıtıEPSS %74dedecms · dedecms27 Mar 2018
- CVE-2015-455352Planlayın
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
YüksekCVSS 8,8Kavram kanıtıEPSS %57dedecms · dedecms6 Oca 2020
- CVE-2023-292850Planlayın
DedeCMS article_allowurl_edit.php code injection
YüksekCVSS 8,8Kavram kanıtıEPSS %51dedecms · dedecms27 May 2023
- CVE-2022-3453146Planlayın
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
KritikCVSS 9,8İstismar yokEPSS %25dedecms · dedecms29 Tem 2022
- CVE-2017-1773143Planlayın
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
KritikCVSS 9,8Kavram kanıtıEPSS %13dedecms · dedecms18 Ara 2017
- CVE-2023-357840Planlayın
DedeCMS co_do.php server-side request forgery
KritikCVSS 9,8Kavram kanıtıEPSS %4dedecms · dedecms10 Tem 2023
- CVE-2022-3551640Planlayın
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
KritikCVSS 9,8İstismar yokEPSS %3dedecms · dedecms17 Ağu 2022
- CVE-2022-2333740Planlayın
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
KritikCVSS 9,8İstismar yokEPSS %2dedecms · dedecms14 Şub 2022
- CVE-2018-917540Planlayın
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code
KritikCVSS 9,8İstismar yokEPSS %2dedecms · dedecms1 Nis 2018
- CVE-2020-1811440Planlayın
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format
KritikCVSS 9,8İstismar yokEPSS %2dedecms · dedecms27 Ağu 2021
- CVE-2018-1906140Planlayın
DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.
KritikCVSS 9,8İstismar yokEPSS %2dedecms · dedecms7 Kas 2018
- CVE-2020-2219840Planlayın
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
KritikCVSS 9,8İstismar yokEPSS %2dedecms · dedecms16 Haz 2021
- CVE-2018-917439İzleyin
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms1 Nis 2018
- CVE-2018-1204539İzleyin
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request wit
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms7 Haz 2018
- CVE-2018-1037539İzleyin
A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to uploa
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms25 Nis 2018
- CVE-2023-3783939İzleyin
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via u
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms13 Tem 2023
- CVE-2023-3484239İzleyin
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /de
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms31 Tem 2023
- CVE-2017-1773039İzleyin
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms18 Ara 2017
- CVE-2026-3069439İzleyin
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms19 Mar 2026
- CVE-2023-205639İzleyin
DedeCMS module_main.php GetSystemFile code injection
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms14 Nis 2023
- CVE-2026-3064339İzleyin
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms1 Nis 2026
- CVE-2024-3551039İzleyin
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via u
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms28 May 2024
- CVE-2023-4078439İzleyin
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms12 Eyl 2023
- CVE-2023-474739İzleyin
DedeCMS tags.php sql injection
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms3 Eyl 2023
- CVE-2024-2966139İzleyin
A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
KritikCVSS 9,8İstismar yokEPSS %1dedecms · dedecms22 Nis 2024