CVE-2024-35375: Dedecms

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS

Affected products

  • Dedecms Dedecms: version 5.7.114 only

Published 2024-05-23. Last modified 2026-06-17.