Dedecms vulnerabilities
164 known vulnerabilities affecting dedecms/dedecms.
Total CVEs
164
CISA KEV
0
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL29HIGH53MEDIUM82
Vulnerabilities
Page 1 of 9
CVE-2018-7700P1HIGHCVSS 8.8ExploitedPoCv5.72018-03-27
CVE-2018-7700 [HIGH] CWE-352 CVE-2018-7700: DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.
nvd
CVE-2017-17731P1CRITICALCVSS 9.8ExploitedPoC≤ 5.72017-12-18
CVE-2017-17731 [CRITICAL] CWE-89 CVE-2017-17731: DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
nvd
CVE-2023-2059P2MEDIUMCVSS 5.3ExploitedPoCv5.7.872023-04-14
CVE-2023-2059 [MEDIUM] CWE-28 CVE-2023-2059: A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issu
A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploads/include/dialog/select_templets.php. The manipulation leads to path traversal: '..\filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identif
nvd
CVE-2015-4553P2HIGHCVSS 8.8PoC≤ 5.6v5.72020-01-06
CVE-2015-4553 [HIGH] CWE-434 CVE-2015-4553: A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
nvd
CVE-2023-3578P2CRITICALCVSS 9.8PoCv5.7.1092023-07-10
CVE-2023-3578 [CRITICAL] CWE-918 CVE-2023-3578: A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability
A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371
nvd
CVE-2018-6910P2HIGHCVSS 7.5PoCv5.72018-02-13
CVE-2018-6910 [HIGH] CWE-668 CVE-2018-6910: DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downm
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
nvd
CVE-2023-2928P2HIGHCVSS 8.8≤ 5.7.106v5.7.1062023-05-27
CVE-2023-2928 [HIGH] CWE-94 CVE-2023-2928: A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by th
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be
nvd
CVE-2024-9076P2HIGHCVSS 8.8≤ 5.7.115v5.7.1152024-09-22
CVE-2024-9076 [HIGH] CWE-77 CVE-2024-9076: A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affect
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about thi
nvd
CVE-2022-34531P2CRITICALCVSS 9.8v5.7.952022-07-29
CVE-2022-34531 [CRITICAL] CVE-2022-34531: DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the compon
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
nvd
CVE-2023-5301P2HIGHCVSS 8.8v5.7.1112023-09-30
CVE-2023-5301 [HIGH] CWE-78 CVE-2023-5301: A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the
A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulner
nvd
CVE-2011-5200P3HIGHCVSS 7.5PoCv5.62012-09-23
CVE-2011-5200 [HIGH] CWE-89 CVE-2011-5200: Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute a
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.
nvd
CVE-2009-3806P3HIGHCVSS 7.5PoCv5.12009-10-27
CVE-2009-3806 [HIGH] CWE-89 CVE-2009-3806: SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arb
SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.
nvd
CVE-2024-11138P2CRITICALCVSS 9.8v5.7.1162024-11-12
CVE-2024-11138 [CRITICAL] CWE-284 CVE-2024-11138: A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown
A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2023-7212P3CRITICALCVSS 9.8≤ 5.7.112v5.7.1122024-01-07
CVE-2023-7212 [CRITICAL] CWE-434 CVE-2023-7212: A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unkno
A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component Backend. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerab
nvd
CVE-2018-20129P3HIGHCVSS 8.8v5.72018-12-13
CVE-2018-20129 [HIGH] CWE-94 CVE-2018-20129: An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows re
An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by the filename=1.jpg.p*hp value.
nvd
CVE-2024-3148P3HIGHCVSS 8.8v5.7.1122024-04-02
CVE-2024-3148 [HIGH] CWE-89 CVE-2024-3148: A vulnerability, which was classified as critical, has been found in DedeCMS 5.7.112. This issue aff
A vulnerability, which was classified as critical, has been found in DedeCMS 5.7.112. This issue affects some unknown processing of the file dede/makehtml_archives_action.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulne
nvd
CVE-2018-9174P3CRITICALCVSS 9.8v5.72018-04-02
CVE-2018-9174 [CRITICAL] CWE-94 CVE-2018-9174: sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refile
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.
nvd
CVE-2023-37839P3CRITICALCVSS 9.8v5.7.1092023-07-13
CVE-2023-37839 [CRITICAL] CWE-434 CVE-2023-37839: An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows a
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
nvd
CVE-2023-34842P3CRITICALCVSS 9.8≤ 5.7.1092023-07-31
CVE-2023-34842 [CRITICAL] CWE-94 CVE-2023-34842: Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitr
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
nvd
CVE-2024-35510P3CRITICALCVSS 9.8v5.7.1142024-05-28
CVE-2024-35510 [CRITICAL] CWE-434 CVE-2024-35510: An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows a
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.
nvd
1 / 9Next →