Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

DedeCMS — Vulnerabilities & Security Advisories 52

All 52 CVE vulnerabilities found in DedeCMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting DedeCMS, a popular content management system originally developed in China, focusing on common weakness classes such as SQL injection, cross-site scripting, and remote code execution issues. It collects historical security advisories and bug reports spanning from the software's initial release through recent patch updates, covering both critical and moderate-severity flaws identified in various versions of the platform. Readers can use this resource to track the vendor's advisory timeline, understand the specific technical nature of the identified weakness categories, and review the complete vulnerability history for DedeCMS instances in their infrastructure.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-94004 DedeCMS mytag_js.php code injection CWE-94 7.3 High 2026-09-20
CVE-2026-76800 DeDeCMS select_media_post.php unrestricted upload CWE-434 6.3 Medium 2026-08-20
CVE-2026-76783 DeDeCMS advancedsearch.php sql injection CWE-89 7.3 High 2026-08-20
CVE-2026-19353 DedeCMS Installation Wizard index.php _4_Setup file inclusion CWE-73 5.0 Medium 2026-08-09
CVE-2026-15700 DedeCMS Album Publishing Feature zip.class.php ExtractFile path traversal CWE-22 4.7 Medium 2026-07-14
CVE-2026-15533 DedeCMS Column Management search.php code injection CWE-94 4.7 Medium 2026-07-13
CVE-2026-10608 DedeCMS carbuyaction.php RemoveXSS sql injection CWE-89 7.3 High 2026-06-02
CVE-2026-10607 DedeCMS flink.php dede_htmlspecialchars sql injection CWE-89 7.3 High 2026-06-02
CVE-2026-10606 DedeCMS Feedback feedback.php TrimMsg sql injection CWE-89 7.3 High 2026-06-02
CVE-2026-10581 DedeCMS download.php base64_decode server-side request forgery CWE-918 6.3 Medium 2026-06-02
CVE-2025-15004 DedeCMS freelist_main.php sql injection CWE-89 6.3 Medium 2025-12-22
CVE-2025-6335 DedeCMS Template dedetag.class.php command injection CWE-77 4.7 Medium 2025-06-20
CVE-2025-5137 DedeCMS Incomplete Fix CVE-2018-9175 sys_verifies.php code injection CWE-94 4.7 Medium 2025-05-25
CVE-2024-12183 DedeCMS HTTP POST Request carbuyaction.php RemoveXSS cross site scripting CWE-79 3.5 Low 2024-12-04
CVE-2024-12182 DedeCMS soft_add.php cross site scripting CWE-79 3.5 Low 2024-12-04
CVE-2024-12181 DedeCMS SWF File uploads_add.php cross site scripting CWE-79 3.5 Low 2024-12-04
CVE-2024-12180 DedeCMS article_add.php cross site scripting CWE-79 3.5 Low 2024-12-04
CVE-2024-11138 DedeCMS friendlink_add.php unrestricted upload CWE-434 2.7 Low 2024-11-12
CVE-2024-9076 DedeCMS article_string_mix.php os command injection CWE-78 4.7 Medium 2024-09-22
CVE-2024-6940 DedeCMS article_template_rand.php code injection CWE-94 4.7 Medium 2024-07-21
CVE-2024-4790 DedeCMS path traversal CWE-24 4.3 Medium 2024-05-11
CVE-2024-4594 DedeCMS sys_safe.php cross-site request forgery CWE-352 4.3 Medium 2024-05-07
CVE-2024-4593 DedeCMS sys_multiserv.php cross-site request forgery CWE-352 4.3 Medium 2024-05-07
CVE-2024-4592 DedeCMS sys_group_edit.php cross-site request forgery CWE-352 4.3 Medium 2024-05-07
CVE-2024-4591 DedeCMS sys_group_add.php cross-site request forgery CWE-352 4.3 Medium 2024-05-07
CVE-2024-4590 DedeCMS sys_info.php cross-site request forgery CWE-352 4.3 Medium 2024-05-07
CVE-2024-4589 DedeCMS mytag_edit.php cross-site request forgery CWE-352 4.3 Medium 2024-05-07
CVE-2024-4588 DedeCMS mytag_add.php cross-site request forgery CWE-352 4.3 Medium 2024-05-07
CVE-2024-4587 DedeCMS tpl.php cross-site request forgery CWE-352 4.3 Medium 2024-05-07
CVE-2024-4586 DedeCMS shops_delivery.php cross-site request forgery CWE-352 4.3 Medium 2024-05-07

All 52 known CVE vulnerabilities affecting DedeCMS with full Chinese analysis, references, and POCs where available.