Junglewise Threat Intelligence

CVE-2026-76783: DeDeCMS SQL injection in advanced search

CVE-2026-76783 · Severity: high · CVSS 7.3 · Published 2026-08-20

Technologies: DedeCMS. Vendors: DedeCMS.

Executive brief

DeDeCMS is a content management system used to publish and manage website content. A SQL injection vulnerability in the advanced search feature allows attackers to manipulate database queries remotely, potentially leading to unauthorized data access, modification, or deletion of database records.

Technical details

The vulnerability is a SQL injection flaw in the /plus/advancedsearch.php file of DeDeCMS 53_1_UTF8, where unsanitized user input in the sql parameter is passed directly to database queries. The attack requires network access but does not require authentication. An attacker can inject malicious SQL commands to extract, modify, or delete data from the application's database. The vulnerability has been disclosed publicly and proof-of-concept code is available.

Affected products

  • DeDeCMS DeDeCMS 53_1_UTF8

Timeline

  • 2026-08-20: disclosed
  • other: Exploit disclosed publicly and may be used in the wild

References

Related threats