Show filters
123 Total Results
Displaying 81-90 of 123
Sort by:
Attacker Value
Unknown

CVE-2020-36494

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.
Attacker Value
Unknown

CVE-2020-36491

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Attacker Value
Unknown

CVE-2020-36495

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `filename`, `mid`, `userid`, and `templet' parameters.
Attacker Value
Unknown

CVE-2020-36496

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.
Attacker Value
Unknown

CVE-2020-36490

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Attacker Value
Unknown

CVE-2020-23044

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Attacker Value
Unknown

CVE-2020-18114

Disclosure Date: August 27, 2021 (last updated February 23, 2025)
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
Attacker Value
Unknown

CVE-2020-18917

Disclosure Date: August 24, 2021 (last updated February 23, 2025)
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Attacker Value
Unknown

CVE-2020-22198

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
Attacker Value
Unknown

CVE-2020-16632

Disclosure Date: May 15, 2021 (last updated February 22, 2025)
A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.