Vulnerability index

Browse CVEs

145 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dedecms MEDIUM 6.1
CVE-2023-49492

DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.

No fix yet
Fix from $1,600 2023-12-07
Dedecms MEDIUM 6.1
CVE-2023-49493

DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php.

No fix yet
Fix from $1,600 2023-12-07
Dedecms HIGH 8.8
CVE-2023-43275

Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create …

No fix yet
Fix from $1,950 2023-11-16
Dedecms MEDIUM 5.4
CVE-2023-48068

DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php.

No fix yet
Fix from $1,600 2023-11-13
Dedecms HIGH 8.8
CVE-2023-5301EPSS 6%

A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. Th…

No fix yet
Fix from $1,950 2023-09-30
Dedecms HIGH 8.8
CVE-2023-43226

An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading …

Fix: after 5.7.111
Fix from $1,950 2023-09-28
Dedecms HIGH 8.8
CVE-2023-5022

A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the…

Fix: after 5.7.100
Fix from $1,950 2023-09-17
Dedecms CRITICAL 9.8
CVE-2023-40784

DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

Mitigation only
Fix from $2,300 2023-09-12
Dedecms CRITICAL 9.8
CVE-2023-4747

A vulnerability classified as critical was found in DedeCMS 5.7.110. This vulnerability affects unknown code of the file /uploads/tags.php. The manip…

Mitigation only
Fix from $2,300 2023-09-04
Dedecms MEDIUM 5.4
CVE-2023-40874

DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the voten…

Fix: after 5.7.110
Fix from $1,600 2023-08-24
Dedecms MEDIUM 5.4
CVE-2023-40875

DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the vote…

Fix: after 5.7.110
Fix from $1,600 2023-08-24
Dedecms MEDIUM 5.4
CVE-2023-40876

DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title para…

Fix: after 5.7.110
Fix from $1,600 2023-08-24
Dedecms MEDIUM 5.4
CVE-2023-40877

DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title par…

Fix: after 5.7.110
Fix from $1,600 2023-08-24
Dedecms HIGH 8.8
CVE-2023-36298

DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).

No fix yet
Fix from $1,950 2023-08-03
Dedecms CRITICAL 9.8
CVE-2023-34842

Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.ph…

Fix: after 5.7.109
Fix from $2,300 2023-07-31
Dedecms CRITICAL 9.8
CVE-2023-37839

An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading …

No fix yet
Fix from $2,300 2023-07-13
Dedecms CRITICAL 9.8
CVE-2023-3578

A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php…

No fix yet
Fix from $2,300 2023-07-10
Dedecms HIGH 8.8
CVE-2023-2928EPSS 51%

A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t…

Fix: after 5.7.106
Fix from $1,950 2023-05-27
Dedecms MEDIUM 5.4
CVE-2023-31757

DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'

No fix yet
Fix from $1,600 2023-05-19
Dedecms HIGH 8.8
CVE-2023-2424

A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uplo…

No fix yet
Fix from $1,950 2023-04-29
Dedecms HIGH 7.5
CVE-2023-30380

An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.

No fix yet
Fix from $1,950 2023-04-27
Dedecms HIGH 7.2
CVE-2023-27733

DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php.

No fix yet
Fix from $1,950 2023-04-17
Dedecms MEDIUM 5.3
CVE-2023-2059

A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploa…

No fix yet
Fix from $1,600 2023-04-14
Dedecms CRITICAL 9.8
CVE-2023-2056

A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.p…

Fix: after 5.7.87
Fix from $2,300 2023-04-14
Dedecms HIGH 7.2
CVE-2023-27707

SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group…

Fix: after 5.7.106
Fix from $1,950 2023-03-16
Dedecms HIGH 7.2
CVE-2023-27709

SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_…

Fix: after 5.7.106
Fix from $1,950 2023-03-16
Dedecms MEDIUM 5.4
CVE-2022-48140

DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view.php?fmdo=edit&filename.

No fix yet
Fix from $1,600 2023-02-02
Dedecms CRITICAL 9.8
CVE-2022-46442

dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.

Fix: after 5.7.102
Fix from $2,300 2022-12-27
Dedecms MEDIUM 6.7
CVE-2022-43192

An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrary code …

No fix yet
Fix from $1,600 2022-11-17
Dedecms HIGH 8.8
CVE-2022-43031

DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and mod…

No fix yet
Fix from $1,950 2022-11-09