CVE-2026-51078

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component

Published 2026-07-27. Last modified 2026-07-28.