Dedecms is a modestly represented content-management system that, despite concentration in a single product line, occupies a prominent position in the landscape owing to widespread deployment particularly in Chinese-language web properties and legacy installations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability reflecting the system's exposure as a web-facing application. The exposure recurs consistently through application-layer weakness classes including cross-site request forgery, cross-site scripting, unrestricted file uploads, code injection, and SQL injection—a pattern characteristic of legacy CMS platforms where input validation and access-control boundaries require ongoing hardening. Defenders should treat Dedecms instances as high-priority for patching and access control, particularly in deployments that remain internet-reachable or handle sensitive content. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dedecms over time
Signals from CVEs in this vendor scope (165 CVEs).
165 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7700HIGH DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP | Mar 27, 2018 | 8.8 | 77 | NO | YES |
CVE-2015-4553HIGH A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell. | Jan 6, 2020 | 8.8 | 63 | NO | YES |
CVE-2023-2928HIGH A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_al | May 27, 2023 | 8.8 | 48 | NO | NO |
CVE-2017-17731CRITICAL DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php. | Dec 18, 2017 | 9.8 | 47 | NO | YES |
CVE-2018-6910HIGH DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php. | Feb 13, 2018 | 7.5 | 44 | NO | YES |
CVE-2023-3578CRITICAL A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argum | Jul 10, 2023 | 9.8 | 39 | NO | YES |
CVE-2024-9076HIGH A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipula | Sep 22, 2024 | 8.8 | 34 | NO | NO |
CVE-2022-34531CRITICAL DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php. | Jul 29, 2022 | 9.8 | 34 | NO | NO |
CVE-2026-30643CRITICAL An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload. | Apr 1, 2026 | 9.8 | 32 | NO | NO |
CVE-2024-57241MEDIUM Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection. | Feb 11, 2025 | 6.5 | 32 | NO | YES |
Signals from CVEs in this vendor scope (165 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dedecms.
Media articles that mention a CVE ID that affects a product developed by Dedecms — matched by CVE ID, not by vendor name.