Show filters
114 Total Results
Displaying 31-40 of 114
Sort by:
Attacker Value
Unknown

CVE-2023-49492

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.
Attacker Value
Unknown

CVE-2023-43275

Disclosure Date: November 16, 2023 (last updated November 21, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.
Attacker Value
Unknown

CVE-2023-48068

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php.
Attacker Value
Unknown

CVE-2023-5301

Disclosure Date: September 30, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240940.
Attacker Value
Unknown

CVE-2023-43226

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
Attacker Value
Unknown

CVE-2023-5022

Disclosure Date: September 17, 2023 (last updated October 08, 2023)
A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863.
Attacker Value
Unknown

CVE-2023-40784

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
Attacker Value
Unknown

CVE-2023-4747

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in DedeCMS 5.7.110. This vulnerability affects unknown code of the file /uploads/tags.php. The manipulation of the argument tag_alias leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238636.
Attacker Value
Unknown

CVE-2023-40877

Disclosure Date: August 24, 2023 (last updated October 08, 2023)
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.
Attacker Value
Unknown

CVE-2023-40876

Disclosure Date: August 24, 2023 (last updated October 08, 2023)
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.