Show filters
114 Total Results
Displaying 41-50 of 114
Sort by:
Attacker Value
Unknown

CVE-2023-40875

Disclosure Date: August 24, 2023 (last updated October 08, 2023)
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters.
Attacker Value
Unknown

CVE-2023-40874

Disclosure Date: August 24, 2023 (last updated October 08, 2023)
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters.
Attacker Value
Unknown

CVE-2023-36298

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).
Attacker Value
Unknown

CVE-2023-34842

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
Attacker Value
Unknown

CVE-2023-37839

Disclosure Date: July 13, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Attacker Value
Unknown

CVE-2023-3578

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371.
Attacker Value
Unknown

CVE-2023-2928

Disclosure Date: May 27, 2023 (last updated October 08, 2023)
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230083.
Attacker Value
Unknown

CVE-2023-31757

Disclosure Date: May 19, 2023 (last updated October 08, 2023)
DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'
Attacker Value
Unknown

CVE-2023-2424

Disclosure Date: April 29, 2023 (last updated October 08, 2023)
A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uploads/dede/config.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227750 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-30380

Disclosure Date: April 27, 2023 (last updated October 08, 2023)
An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.