Known Vulnerabilities for DedeCMS by Na
Listed below are 8 of the newest known vulnerabilities associated with "DedeCMS" by "Na".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94004 json | A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php... | Not Provided | 2026-09-20 | 2026-09-20 |
| CVE-2026-76800 json | A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/se... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-76783 json | A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/ad... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-19353 json | A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file in... | Not Provided | 2026-08-09 | 2026-08-11 |
| CVE-2026-15700 json | A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the fil... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-15533 json | A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the c... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2023-49494 json | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_med... | Not Provided | 2023-12-11 | 2026-07-09 |
| CVE-2023-34842 json | Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST... | Not Provided | 2023-07-31 | 2026-07-09 |