dedecms是dedecms团队的一套内容管理系统软件。 DesDev DedeCMS 5.7.118版本存在路径遍历漏洞,该漏洞源于Album Publishing Feature组件中include/zip.class.php文件的ExtractFile函数对参数filename的操作导致路径遍历,攻击者可远程执行攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | DedeCMS | 5.7.118 |
cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15702 | 6.3 MEDIUM | tamagui config.ts updateConfig prototype pollution |
| CVE-2026-15690 | 3.1 LOW | open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer deref |
| CVE-2026-51105 | amule 缓冲区错误漏洞 | |
| CVE-2026-52101 | Andrei Marcu linx-server 安全漏洞 | |
| CVE-2026-52100 | Andrei Marcu linx-server 安全漏洞 | |
| CVE-2026-38450 | Aetopia Digital Asset Management DAM 安全漏洞 | |
| CVE-2025-56361 | Connectivity Standards Alliance Matter 安全漏洞 | |
| CVE-2025-56364 | Connectivity Standards Alliance Matter 安全漏洞 | |
| CVE-2025-56365 | Connectivity Standards Alliance Matter 安全漏洞 | |
| CVE-2025-56362 | Connectivity Standards Alliance Matter 安全漏洞 | |
| CVE-2025-56363 | Connectivity Standards Alliance Matter 安全漏洞 | |
| CVE-2026-36035 | CAXperts UniversalPlantViewer WebServices Server 安全漏洞 | |
| CVE-2026-51807 | Osamu Watanabe OpenHTJ2K 安全漏洞 | |
| CVE-2026-51808 | Osamu Watanabe OpenHTJ2K 安全漏洞 |
No comments yet