DedeCMS Code Injection Vulnerability in Column Management Component

Vulnerability

A code injection vulnerability has been identified in DedeCMS version 5.7.118, specifically within the Column Management feature. The issue arises in an unknown function of the file '/plus/search.php', where manipulation of the 'Column Name' argument allows for remote code execution. The vulnerability has been publicly disclosed and could be exploited by attackers.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where DedeCMS is installed.

Added: Jul 13, 2026, 6:24 AM
Updated: Jul 13, 2026, 6:24 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
7.5
exploitability
9.7
remediation
0.0
relevance
9.2
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.