Vulnerabilities
Vulnerable Software
Dedecms:  >> Dedecms  >> 5.7.93  Security Vulnerabilities
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-08-24
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-08-24
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
CVSS Score
9.8
EPSS Score
0.021
Published
2023-07-31
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230083.
CVSS Score
6.3
EPSS Score
0.603
Published
2023-05-27
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint.
CVSS Score
7.2
EPSS Score
0.009
Published
2023-03-16
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.
CVSS Score
7.2
EPSS Score
0.009
Published
2023-03-16
dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.
CVSS Score
9.8
EPSS Score
0.001
Published
2022-12-27
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
CVSS Score
9.8
EPSS Score
0.056
Published
2022-08-17
DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.
CVSS Score
6.5
EPSS Score
0.002
Published
2022-05-26


Contact Us

Shodan ® - All rights reserved