Junglewise Threat Intelligence

CVE-2026-10606: DedeCMS SQL injection in Feedback Handler

CVE-2026-10606 · Severity: high · CVSS 7.3 · Published 2026-06-02

Technologies: DedeCMS. Vendors: DedeCMS.

Executive brief

DedeCMS, a popular content management system, contains a security flaw in its feedback handling component. An attacker can exploit this vulnerability to interfere with the website's database, potentially leading to unauthorized data access or modification. Because the exploit is publicly available, the risk of unauthorized parties attempting to compromise affected websites is increased.

Technical details

A SQL injection vulnerability exists in DedeCMS 5.7.88 within the Feedback Handler component. The flaw is located in the TrimMsg function in the /plus/feedback.php file. By manipulating the 'msg' parameter, a remote, unauthenticated attacker can inject malicious SQL commands into the application's database queries. This vulnerability can be exploited over the network without user interaction. Successful exploitation could allow an attacker to read, modify, or delete sensitive information from the database. A public exploit has been disclosed.

Affected products

  • DedeCMS DedeCMS 5.7.88

Timeline

  • 2026-06-02: disclosed: Vulnerability and exploit details publicly disclosed.
  • 2026-06-02: advisory: NVD published the CVE record.

References

Related threats