{"api_version":"1","generated_at":"2026-07-23T14:02:23+00:00","cve":"CVE-2020-27533","urls":{"html":"https://cve.report/CVE-2020-27533","api":"https://cve.report/api/cve/CVE-2020-27533.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-27533","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-27533"},"summary":{"title":"CVE-2020-27533","description":"A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-10-22 15:15:00","updated_at":"2022-06-03 18:56:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.html","name":"http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.html","refsource":"MISC","tags":[],"title":"DedeCMS 5.8 Cross Site Scripting ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/dedetech/issues/issues/16","name":"https://github.com/dedetech/issues/issues/16","refsource":"MISC","tags":["Exploit","Issue Tracking","Third Party Advisory"],"title":"Cross-Site Scripting · Issue #16 · dedetech/issues · GitHub","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-27533","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-27533","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"27533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dedecms","cpe5":"dedecms","cpe6":"5.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"27533","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dedecms","cpe5":"dedecms","cpe6":"5.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-27533","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/dedetech/issues/issues/16","refsource":"MISC","name":"https://github.com/dedetech/issues/issues/16"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.html","url":"http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.html"}]}},"nvd":{"publishedDate":"2020-10-22 15:15:00","lastModifiedDate":"2022-06-03 18:56:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:dedecms:dedecms:5.8:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"27533","Ordinal":"188967","Title":"CVE-2020-27533","CVE":"CVE-2020-27533","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"27533","Ordinal":"1","NoteData":"A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"27533","Ordinal":"2","NoteData":"2020-10-22","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"27533","Ordinal":"3","NoteData":"2020-10-30","Type":"Other","Title":"Modified"}]}}}