Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Dunkboy

#22659de 56,330
11.6CVSS total
Vulnerabilidades · 2
Média
2
PT-2026-58101
5.8
2026-07-14
Undefined · Undefined · CVE-2026-15700
A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
PT-2026-57627
5.8
2026-07-13
Dedecms · Dedecms · CVE-2026-15533
**Nome do Software Vulnerável e Versões Afetadas** DedeCMS versão 5.7.118 **Description** Uma falha de injeção de código remoto existe no componente Column Management no endpoint `/plus/search.php`. O problema ocorre quando o argumento `Column Name` é manipulado, permitindo que um invasor execute código arbitrário remotamente. **Recommendations** No momento, não há informações sobre uma versão mais recente que contenha a correção para esta vulnerabilidade. Restrinja o acesso ao endpoint `/plus/search.php` para minimizar o risco de exploração.