Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dedecms vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2024-4586
A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/shops_delivery.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclose...
NA
CVE-2024-4587
A vulnerability was found in DedeCMS 5.7 and classified as problematic. This issue affects some unknown processing of the file /src/dede/tpl.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the publ...
NA
CVE-2024-4588
A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed...
NA
CVE-2024-4589
A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit h...
NA
CVE-2024-4585
A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/member_type.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed...
NA
CVE-2024-33749
DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
NA
CVE-2024-33371
Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote malicious user to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component.
NA
CVE-2024-33401
Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote malicious user to run arbitrary code via the mnum parameter.
NA
CVE-2024-29660
Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local malicious user to execute arbitrary code via a crafted payload to the stepselect_main.php component.
NA
CVE-2024-29661
A File Upload vulnerability in DedeCMS v5.7 allows a local malicious user to execute arbitrary code via a crafted payload.
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4541
CVE-2024-3080
CVE-2024-4787
log injection
CVE-2024-5967
inject
CVE-2024-30078
CVE-2024-5899
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »