Dedecms · Dedecms · CVE-2026-76800
**Name of the Vulnerable Software and Affected Versions**
DeDeCMS version 3
**Description**
A flaw in the `/include/dialog/select media post.php` file allows for unrestricted file upload. This occurs when the `uploadfile` argument is manipulated, enabling a remote attacker to upload files to the server.
**Recommendations**
As a temporary workaround, restrict access to the `/include/dialog/select media post.php` file or disable the functionality associated with the `uploadfile` parameter until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.