Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 07 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | DedeCMS 5.7.118 Code Injection via Module Upload Setup Tags |
Mon, 06 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:* |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | DedeCMS 5.7.118 Code Injection via Module Upload Setup Tags | |
| First Time appeared |
Dedecms
Dedecms dedecms |
|
| Vendors & Products |
Dedecms
Dedecms dedecms |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload. | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-01T18:14:10.109Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30643
Updated: 2026-04-01T18:11:03.749Z
Status : Analyzed
Published: 2026-04-01T17:28:39.003
Modified: 2026-04-06T15:29:18.880
Link: CVE-2026-30643
No data.
OpenCVE Enrichment
Updated: 2026-04-07T08:07:43Z