Loading HuntDB...

Vulnerabilities

CVE-2024-28665

UNKNOWN

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_add.php

Published Mar 13, 2024

CVE-2024-28677

UNKNOWN

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/article_keywords_main.php.

Published Mar 13, 2024

CVE-2024-28675

UNKNOWN

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php

Published Mar 13, 2024

CVE-2024-28683

UNKNOWN

DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via create file.

Published Mar 13, 2024

CVE-2024-28431

UNKNOWN

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.

Published Mar 13, 2024

CVE-2023-49453

UNKNOWN

Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php.

Published Mar 12, 2024

CVE-2024-25327

UNKNOWN

Cross Site Scripting (XSS) vulnerability in Justice Systems FullCourt Enterprise v.8.2 allows a remote attacker to execute arbitrary code via the formatCaseNumber parameter of the Citation search function.

Published Mar 07, 2024

CVE-2023-52047

UNKNOWN

Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.

Published Feb 28, 2024

CVE-2023-43275

UNKNOWN

Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.

Published Nov 16, 2023

CVE-2023-40784

UNKNOWN

DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

Published Sep 12, 2023