Vulnerabilities (CVE)

Filtered by vendor Dedecms Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-7212 1 Dedecms 1 Dedecms 2024-01-11 N/A 9.8 CRITICAL
A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component Backend. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249768. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-34842 1 Dedecms 1 Dedecms 2023-08-04 N/A 9.8 CRITICAL
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
CVE-2023-37839 1 Dedecms 1 Dedecms 2023-07-27 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2022-23337 1 Dedecms 1 Dedecms 2022-02-22 7.5 HIGH 9.8 CRITICAL
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
CVE-2020-18114 1 Dedecms 1 Dedecms 2021-09-01 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
CVE-2020-22198 1 Dedecms 1 Dedecms 2021-06-21 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
CVE-2018-19061 1 Dedecms 1 Dedecms 2018-12-10 7.5 HIGH 9.8 CRITICAL
DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.
CVE-2018-12045 1 Dedecms 1 Dedecms 2018-07-27 7.5 HIGH 9.8 CRITICAL
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.
CVE-2018-10375 1 Dedecms 1 Dedecms 2018-06-13 7.5 HIGH 9.8 CRITICAL
A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and execute arbitrary PHP code via the /dede/archives_do.php?dopost=uploadLitpic litpic parameter when "Content-Type: image/jpeg" is sent, but the filename ends in .php and contains PHP code.
CVE-2018-9175 1 Dedecms 1 Dedecms 2018-05-02 7.5 HIGH 9.8 CRITICAL
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.
CVE-2018-9174 1 Dedecms 1 Dedecms 2018-05-02 7.5 HIGH 9.8 CRITICAL
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.
CVE-2017-17731 1 Dedecms 1 Dedecms 2018-01-04 7.5 HIGH 9.8 CRITICAL
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
CVE-2017-17730 1 Dedecms 1 Dedecms 2018-01-04 7.5 HIGH 9.8 CRITICAL
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.