📦 Dedecms

by Dedecms

🔍 What is Dedecms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-35510

CRITICAL CVSS 9.8 May 28, 2024

This critical vulnerability in DedeCMS allows attackers to upload arbitrary files to the server, leading to remote code execution. Attackers can compromise the entire web server by uploading malicious...

CVE-2024-35375

CRITICAL CVSS 9.8 May 23, 2024

This vulnerability allows unauthenticated attackers to upload arbitrary files to DedeCMS backend servers via the media_add.php page. Attackers can achieve remote code execution by uploading malicious ...

CVE-2024-33749

CRITICAL CVSS 9.1 May 6, 2024

DedeCMS V5.7.114 contains an improper authorization vulnerability in mail_file_manage.php that allows attackers to delete any file on the server. This affects all DedeCMS installations running the vul...

CVE-2024-29661

CRITICAL CVSS 9.8 Apr 22, 2024

This CVE describes a critical file upload vulnerability in DedeCMS v5.7 that allows local attackers to upload malicious files and execute arbitrary code on the server. The vulnerability affects all De...

CVE-2024-29684

CRITICAL CVSS 9.8 Mar 26, 2024

DedeCMS v5.7 contains a CSRF vulnerability in the makehtml_homepage.php component that allows attackers to trick authenticated administrators into executing arbitrary code. This affects all DedeCMS v5...

CVE-2023-40784

CRITICAL CVSS 9.8 Sep 12, 2023

DedeCMS 5.7.102 contains an unrestricted file upload vulnerability in the module_make.php component that allows attackers to upload arbitrary files, including malicious scripts. This affects all DedeC...

CVE-2023-34842

CRITICAL CVSS 9.8 Jul 31, 2023

This critical vulnerability in DedeCMS allows remote attackers to execute arbitrary code on affected systems by sending specially crafted POST requests to the /dede/tpl.php endpoint. All DedeCMS insta...

CVE-2023-37839

CRITICAL CVSS 9.8 Jul 13, 2023

This vulnerability allows attackers to upload arbitrary PHP files to DedeCMS v5.7.109 through the /dede/file_manage_control.php endpoint, leading to remote code execution. Attackers can gain full cont...

CVE-2022-34531

CRITICAL CVSS 9.8 Jul 29, 2022

DedeCMS v5.7.95 contains a remote code execution vulnerability in the mytag_main.php component that allows attackers to execute arbitrary code on affected systems. This affects all websites running th...

CVE-2020-22198

CRITICAL CVSS 9.8 Jun 16, 2021

This CVE describes a SQL injection vulnerability in DedeCMS 5.7 that allows attackers to execute arbitrary SQL commands via the mdescription parameter in member/ajax_membergroup.php. This affects all ...

CVE-2024-30855

HIGH CVSS 8.8 Dec 29, 2025

DedeCMS v5.7 contains a CSRF vulnerability in the makehtml_list_action.php file that allows attackers to trick authenticated administrators into performing unauthorized actions. This affects all DedeC...

CVE-2024-46373

HIGH CVSS 8.8 Sep 18, 2024

Dedecms V5.7.115 contains a file upload vulnerability in the backend that allows authenticated attackers to upload malicious files and execute arbitrary code. This affects websites running this specif...

CVE-2024-30965

HIGH CVSS 8.8 Apr 2, 2024

DedeCMS v5.7 contains a CSRF vulnerability in the member_scores.php component that allows attackers to trick authenticated administrators into performing unauthorized actions. This affects all DedeCMS...

CVE-2024-28671

HIGH CVSS 8.8 Mar 13, 2024

DedeCMS v5.7 contains a Cross-Site Request Forgery (CSRF) vulnerability in the /dede/stepselect_main.php endpoint. This allows attackers to trick authenticated administrators into performing unintende...

CVE-2024-28673

HIGH CVSS 8.8 Mar 13, 2024

DedeCMS v5.7 contains a CSRF vulnerability in the mychannel_edit.php component that allows attackers to trick authenticated administrators into performing unauthorized actions. This affects all DedeCM...

CVE-2024-28675

HIGH CVSS 8.8 Mar 13, 2024

DedeCMS v5.7 contains a CSRF vulnerability in the /dede/diy_edit.php endpoint that allows attackers to trick authenticated administrators into performing unauthorized actions. This affects all DedeCMS...

CVE-2024-28665

HIGH CVSS 8.8 Mar 13, 2024

DedeCMS v5.7 contains a Cross-Site Request Forgery (CSRF) vulnerability in the article_add.php component that allows attackers to trick authenticated administrators into performing unauthorized action...

CVE-2024-28431

HIGH CVSS 8.8 Mar 13, 2024

DedeCMS v5.7 contains a CSRF vulnerability in the catalog_del.php component that allows attackers to trick authenticated administrators into performing unauthorized catalog deletion actions. This affe...

CVE-2023-52047

HIGH CVSS 8.8 Feb 28, 2024

This CSRF vulnerability in Dedecms v5.7.112 allows attackers to trick authenticated administrators into performing unauthorized actions via the file manager. Attackers can upload malicious files, modi...

CVE-2024-22895

HIGH CVSS 8.8 Jan 22, 2024

DedeCMS 5.7.112 contains an unrestricted file upload vulnerability in the module_upload.php component. Attackers can upload malicious files to execute arbitrary code on affected systems. This affects ...

CVE-2023-27733

HIGH CVSS 7.2 Apr 17, 2023

DedeCMS v5.7.106 contains a SQL injection vulnerability in the /dede/sys_sql_query.php component that allows authenticated attackers to execute arbitrary SQL commands. This affects administrators with...

CVE-2023-27707

HIGH CVSS 7.2 Mar 16, 2023

This SQL injection vulnerability in DedeCMS allows remote attackers to execute arbitrary SQL commands through the rank_* parameter in the /dede/group_store.php endpoint. Attackers can potentially read...

CVE-2025-15004

MEDIUM CVSS 6.3 Dec 22, 2025

This SQL injection vulnerability in DedeCMS allows attackers to manipulate database queries through the orderby parameter in /freelist_main.php. Attackers can potentially read, modify, or delete datab...

CVE-2025-5137

MEDIUM CVSS 4.7 May 25, 2025

This CVE describes a critical code injection vulnerability in DedeCMS 5.7.117 that allows remote attackers to execute arbitrary code by manipulating the 'refiles' parameter in the sys_verifies.php fil...

CVE-2024-6940

MEDIUM CVSS 4.7 Jul 21, 2024

This critical vulnerability in DedeCMS allows remote attackers to inject and execute arbitrary code through the article_template_rand.php file. It affects all users running DedeCMS 5.7.114, potentiall...

CVE-2024-34959

MEDIUM CVSS 5.5 May 17, 2024

DedeCMS V5.7.113 contains a cross-site scripting vulnerability in sys_data_replace.php that allows attackers to inject malicious scripts into web pages. This affects administrators and users who view ...

CVE-2024-4594

MEDIUM CVSS 4.3 May 7, 2024

This CSRF vulnerability in DedeCMS 5.7 allows attackers to trick authenticated administrators into performing unintended actions by visiting malicious web pages. It affects all DedeCMS 5.7 installatio...

CVE-2024-4591

MEDIUM CVSS 4.3 May 7, 2024

This CSRF vulnerability in DedeCMS 5.7 allows attackers to trick authenticated administrators into performing unauthorized actions via the /src/dede/sys_group_add.php endpoint. Attackers can remotely ...

CVE-2024-4593

MEDIUM CVSS 4.3 May 7, 2024

This vulnerability in DedeCMS 5.7 allows attackers to perform cross-site request forgery (CSRF) attacks via the /src/dede/sys_multiserv.php file. Attackers can trick authenticated users into performin...

CVE-2024-4587

MEDIUM CVSS 4.3 May 7, 2024

This CSRF vulnerability in DedeCMS allows attackers to trick authenticated administrators into performing unintended actions by visiting malicious web pages. It affects DedeCMS 5.7 installations using...

CVE-2024-4589

MEDIUM CVSS 4.3 May 7, 2024

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS 5.7 that allows attackers to trick authenticated users into performing unintended actions via the /src/dede/mytag_edit.p...

CVE-2024-4585

MEDIUM CVSS 4.3 May 7, 2024

This CSRF vulnerability in DedeCMS 5.7 allows attackers to trick authenticated users into performing unintended actions by manipulating the /src/dede/member_type.php file. Attackers can exploit this r...