Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dedebiz

First CVE: Aug 17, 2022Active for: 4 yearsTotal CVEs: 31
50.0
VTI Score
TOP TARGET

Dedebiz is a content management and web-publishing platform that, despite a narrow product focus concentrated in DedeCMS and related tools, occupies a more prominent niche within the vulnerability landscape than its modest volume might initially suggest. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur persistently through application-layer weakness classes including SQL injection, cross-site scripting, unrestricted file uploads, and downstream injection patterns that are characteristic of web-facing CMS platforms. The exposure reflects the inherent risk of handling user input and file uploads in a widely deployed publishing system where parsing and output-encoding boundaries are frequent attack vectors. Defenders should prioritize inventory and patching of DedeCMS instances, particularly internet-reachable deployments, since the recurring weakness classes present direct routes to authentication bypass, content compromise, and code execution. Current exploitation activity, exposure counts, and severity figures are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
3.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dedebiz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 17, 2022
3 years ago
Most Recent CVE
Dec 14, 2025
222 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-31546CRITICAL
Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.
Dec 14, 20239.653NONO
CVE-2023-43234CRITICAL
DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.
Sep 27, 20239.833NONO
CVE-2022-44120CRITICAL
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
Nov 23, 20229.831NONO
CVE-2022-44118CRITICAL
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
Nov 23, 20229.831NONO
CVE-2024-52770CRITICAL
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
Nov 20, 20249.830NONO
CVE-2022-43196CRITICAL
dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.
Nov 23, 20229.128NONO
CVE-2025-14648HIGH
A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown functionality of the file /src/admin/catalog_add.php. Such manipulat
Dec 14, 20257.227NONO
CVE-2024-7903HIGH
A vulnerability was found in DedeBIZ 6.3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/media_add.php of the comp
Aug 18, 20248.827NONO
CVE-2024-7906HIGH
A vulnerability classified as critical was found in DedeBIZ 6.3.0. This vulnerability affects the function get_mime_type of the file /admin/dialog/select_images_post.php of the com
Aug 18, 20248.826NONO
CVE-2024-7904HIGH
A vulnerability was found in DedeBIZ 6.3.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/file_manage_control.php of the com
Aug 18, 20248.826NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
23%
55%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None23 (74.2%)
Unknown0 (0.0%)
Required8 (25.8%)
Privileges Required
Low6 (19.4%)
High16 (51.6%)
None9 (29.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dedebiz.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dedebiz — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dedebiz's Products

View all 2 CNAs →

Top CWEs