Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/ysl1415926/DedeCMS

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Join the discussion
0

DedeCMS version 5.7.118 contains a code injection vulnerability in the /plus/search.php file within the Column Management component. The vulnerability arises from improper handling of the 'Column Name' argument, allowing remote attackers to inject code. This issue has a medium severity rating with a CVSS score of 5.1. No official patch or remediation guidance is currently available, and public exploit code has been released.

Join the discussion
0

A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

Join the discussion
0

A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

Join the discussion
0

A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Join the discussion
0

DedeCMS version 5.7.88 contains a server-side request forgery (SSRF) vulnerability in the base64_decode function within /plus/download.php when the 'Link' parameter is manipulated. This flaw allows remote attackers to cause the server to make unintended requests. The vulnerability has a medium severity score of 5.3 and an exploit has been published. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion
CVE-2026-29839: n/aCVE-2026-29839
0

DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.

Join the discussion
CVE-2026-30694: n/aCVE-2026-30694
0

An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

Join the discussion
0

A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Join the discussion
CVE-2024-42636: n/aCVE-2024-42636
0

DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Package: pkg:github/ysl1415926/DedeCMS
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses