CVE-2022-48140: Dedecms

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view.php?fmdo=edit&filename.

Affected products

  • Dedecms Dedecms: version 5.7.97 only

Published 2023-02-02. Last modified 2026-06-17.