Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
dedecms dedecms 5.7