← Back

Dedecms

dedecms

165 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Dedecms
dedecms

CVEs (165)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dedecms
1Dedecms
May 13, 2026
Dec 18, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parameter to member/article_edit.php.
1Dedecms
1Dedecms
Apr 29, 2026
Sep 23, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.
1Dedecms
1Dedecms
Apr 29, 2026
Mar 24, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] paramet...Show more
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.Show less
1Dedecms
1Dedecms
Apr 23, 2026
Oct 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.
1Dedecms
1Dedecms
Apr 23, 2026
Jul 1, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via...Show more
Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via unspecified vectors, as demonstrated by a .jpg.php filename.Show less