Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dunkboy

#22639of 56,326
11.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-58101
5.8
2026-07-14
Undefined · Undefined · CVE-2026-15700
A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
PT-2026-57627
5.8
2026-07-13
Dedecms · Dedecms · CVE-2026-15533
**Name of the Vulnerable Software and Affected Versions** DedeCMS version 5.7.118 **Description** A remote code injection flaw exists within the Column Management component in the `/plus/search.php` endpoint. The issue occurs when the `Column Name` argument is manipulated, allowing an attacker to execute arbitrary code remotely. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict access to the `/plus/search.php` endpoint to minimize the risk of exploitation.