CVE-2023-27709: Dedecms
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.
Affected products
- Dedecms Dedecms: up to and including 5.7.106
Published 2023-03-16. Last modified 2026-06-17.