Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dedecms

First CVE: Jul 1, 2009Active for: 17 yearsTotal CVEs: 165
50.3
VTI Score
TOP TARGET

Dedecms is a modestly represented content-management system that, despite concentration in a single product line, occupies a prominent position in the landscape owing to widespread deployment particularly in Chinese-language web properties and legacy installations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability reflecting the system's exposure as a web-facing application. The exposure recurs consistently through application-layer weakness classes including cross-site request forgery, cross-site scripting, unrestricted file uploads, code injection, and SQL injection—a pattern characteristic of legacy CMS platforms where input validation and access-control boundaries require ongoing hardening. Defenders should treat Dedecms instances as high-priority for patching and access control, particularly in deployments that remain internet-reachable or handle sensitive content. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
165
Total CVEs
More Total CVEs than 100% of tracked vendors
12.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dedecms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2009
17 years ago
Most Recent CVE
Apr 1, 2026
114 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (165 CVEs).

165 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7700HIGH
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP
Mar 27, 20188.877NOYES
CVE-2015-4553HIGH
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
Jan 6, 20208.863NOYES
CVE-2023-2928HIGH
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_al
May 27, 20238.848NONO
CVE-2017-17731CRITICAL
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
Dec 18, 20179.847NOYES
CVE-2018-6910HIGH
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
Feb 13, 20187.544NOYES
CVE-2023-3578CRITICAL
A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argum
Jul 10, 20239.839NOYES
CVE-2024-9076HIGH
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipula
Sep 22, 20248.834NONO
CVE-2022-34531CRITICAL
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
Jul 29, 20229.834NONO
CVE-2026-30643CRITICAL
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
Apr 1, 20269.832NONO
CVE-2024-57241MEDIUM
Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.
Feb 11, 20256.532NOYES
View all 165 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products165 CVEs
50%
32%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (1.8%)
Network158 (95.8%)
Unknown4 (2.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low161 (97.6%)
High0 (0.0%)
Unknown4 (2.4%)
User Interaction
None70 (42.4%)
Unknown4 (2.4%)
Required91 (55.2%)
Privileges Required
Low42 (25.5%)
High13 (7.9%)
None106 (64.2%)
Unknown4 (2.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (165 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
8 CVEs
4.8% of CVEs· 96th percentile
ExploitDB
4 CVEs
2.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dedecms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dedecms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dedecms's Products

View all 2 CNAs →

Top CWEs