Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-94004— DedeCMS mytag_js.php code injection

Quick assessment

Affected
n/a DedeCMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 DedeCMS 5.7.118 及更早版本中发现了一个漏洞。该漏洞涉及文件 中一个未知函数的参数 未经验证或过滤不当,导致可能引发代码注入攻击。该攻击可远程发起,且相关漏洞利用代码已公开,可能被攻击者利用。

CVSS 7.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94004

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DedeCMS mytag_js.php code injection
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument aid results in code injection. The attack can be launched remotely. The exploit has been made public and could be used.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- DedeCMS 5.7.118 cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-94004

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94004

登录查看更多情报信息。

Same Patch Batch · n/a · 2026-09-20 · 4 CVEs total

CVE-2026-93962 8.3 HIGH Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow
CVE-2026-93960 4.3 MEDIUM Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication
CVE-2026-94030 3.1 LOW SerenityOS LibGfx BMPLoader.cpp decode_bmp_pixel_data integer overflow

IV. Related Vulnerabilities

V. Comments for CVE-2026-94004

No comments yet


Leave a comment