CVE-2023-27707: Dedecms

High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.

SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint.

Affected products

  • Dedecms Dedecms: up to and including 5.7.106

Published 2023-03-16. Last modified 2026-06-17.