Vulnerabilities (CVE)

Filtered by vendor Dedecms Subscribe
Filtered by product Dedecms
Total 158 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3578 1 Dedecms 1 Dedecms 2024-11-21 5.2 MEDIUM 5.5 MEDIUM
A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371.
CVE-2023-37839 1 Dedecms 1 Dedecms 2024-11-21 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2023-36298 1 Dedecms 1 Dedecms 2024-11-21 N/A 8.8 HIGH
DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).
CVE-2023-34842 1 Dedecms 1 Dedecms 2024-11-21 N/A 9.8 CRITICAL
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
CVE-2023-2928 1 Dedecms 1 Dedecms 2024-11-21 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230083.
CVE-2023-2424 1 Dedecms 1 Dedecms 2024-11-21 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uploads/dede/config.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227750 is the identifier assigned to this vulnerability.
CVE-2023-2059 1 Dedecms 1 Dedecms 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploads/include/dialog/select_templets.php. The manipulation leads to path traversal: '..\filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225944.
CVE-2023-2056 1 Dedecms 1 Dedecms 2024-11-21 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225941 was assigned to this vulnerability.
CVE-2022-43192 1 Dedecms 1 Dedecms 2024-11-21 N/A 6.7 MEDIUM
An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is related to an incomplete fix for CVE-2022-40886.
CVE-2022-43031 1 Dedecms 1 Dedecms 2024-11-21 N/A 8.8 HIGH
DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.
CVE-2022-40921 1 Dedecms 1 Dedecms 2024-11-21 N/A 7.2 HIGH
DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.
CVE-2022-40886 1 Dedecms 1 Dedecms 2024-11-21 N/A 7.2 HIGH
DedeCMS 5.7.98 has a file upload vulnerability in the background.
CVE-2022-36583 1 Dedecms 1 Dedecms 2024-11-21 N/A 6.1 MEDIUM
DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters.
CVE-2022-36216 1 Dedecms 1 Dedecms 2024-11-21 N/A 7.2 HIGH
DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.
CVE-2022-35516 1 Dedecms 1 Dedecms 2024-11-21 N/A 9.8 CRITICAL
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
CVE-2022-34531 1 Dedecms 1 Dedecms 2024-11-21 N/A 9.8 CRITICAL
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
CVE-2022-30508 1 Dedecms 1 Dedecms 2024-11-21 5.5 MEDIUM 6.5 MEDIUM
DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.
CVE-2022-23337 1 Dedecms 1 Dedecms 2024-11-21 7.5 HIGH 9.8 CRITICAL
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
CVE-2021-32073 1 Dedecms 1 Dedecms 2024-11-21 6.8 MEDIUM 8.8 HIGH
DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.
CVE-2020-36497 1 Dedecms 1 Dedecms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.