Dedebiz is a content management and web-publishing platform that, despite a narrow product focus concentrated in DedeCMS and related tools, occupies a more prominent niche within the vulnerability landscape than its modest volume might initially suggest. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur persistently through application-layer weakness classes including SQL injection, cross-site scripting, unrestricted file uploads, and downstream injection patterns that are characteristic of web-facing CMS platforms. The exposure reflects the inherent risk of handling user input and file uploads in a widely deployed publishing system where parsing and output-encoding boundaries are frequent attack vectors. Defenders should prioritize inventory and patching of DedeCMS instances, particularly internet-reachable deployments, since the recurring weakness classes present direct routes to authentication bypass, content compromise, and code execution. Current exploitation activity, exposure counts, and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dedebiz over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31546CRITICAL Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature. | Dec 14, 2023 | 9.6 | 53 | NO | NO |
CVE-2023-43234CRITICAL DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters. | Sep 27, 2023 | 9.8 | 33 | NO | NO |
CVE-2022-44120CRITICAL dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. | Nov 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-44118CRITICAL dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php. | Nov 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-52770CRITICAL An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file. | Nov 20, 2024 | 9.8 | 30 | NO | NO |
CVE-2022-43196CRITICAL dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php. | Nov 23, 2022 | 9.1 | 28 | NO | NO |
CVE-2025-14648HIGH A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown functionality of the file /src/admin/catalog_add.php. Such manipulat | Dec 14, 2025 | 7.2 | 27 | NO | NO |
CVE-2024-7903HIGH A vulnerability was found in DedeBIZ 6.3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/media_add.php of the comp | Aug 18, 2024 | 8.8 | 27 | NO | NO |
CVE-2024-7906HIGH A vulnerability classified as critical was found in DedeBIZ 6.3.0. This vulnerability affects the function get_mime_type of the file /admin/dialog/select_images_post.php of the com | Aug 18, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-7904HIGH A vulnerability was found in DedeBIZ 6.3.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/file_manage_control.php of the com | Aug 18, 2024 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dedebiz.
Media articles that mention a CVE ID that affects a product developed by Dedebiz — matched by CVE ID, not by vendor name.