CVE-2020-18114: Dedecms

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.

Affected products

Published 2021-08-27. Last modified 2026-06-17.