Junglewise Threat Intelligence

CVE-2026-15533: DedeCMS code injection in Column Management via search.php

CVE-2026-15533 · Severity: medium · CVSS 4.7 · Published 2026-07-13

Technologies: DedeCMS. Vendors: DedeCMS.

Executive brief

DedeCMS, a popular content management system, contains a security flaw in its Column Management component. An attacker with administrative privileges can inject malicious code into the system by manipulating column names. This could allow an attacker to gain unauthorized control over the website, potentially leading to data theft or a complete site takeover.

Technical details

A code injection vulnerability exists in DedeCMS 5.7.118 within the Column Management component, specifically involving the /plus/search.php file. The root cause is improper neutralization of special elements in the 'Column Name' argument, which is subsequently written to a cache file. An authenticated attacker with high privileges (PR:H) can exploit this via a network request to achieve remote code execution (RCE). While the CVSS score is moderate due to the requirement for high privileges, a public exploit has been released, increasing the risk of exploitation in environments where administrative accounts are compromised.

Affected products

  • DedeCMS DedeCMS 5.7.118

Timeline

  • 2026-07-13: disclosed: Vulnerability published to NVD and VulDB.

References

Related threats