CVE-2020-18917: Dedecms
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Affected products
- Dedecms Dedecms: version 5.7 only
Published 2021-08-24. Last modified 2026-06-17.