Junglewise Threat Intelligence

CVE-2026-94004: DedeCMS code injection in plus/mytag_js.php

CVE-2026-94004 · Severity: high · CVSS 7.3 · Published 2026-09-20

Technologies: DedeCMS. Vendors: DedeCMS.

Executive brief

DedeCMS is a content management system used to publish and manage website content. A vulnerability in the plus/mytag_js.php file allows remote attackers to inject and execute arbitrary code through the aid parameter, potentially giving them full control of the website and underlying server.

Technical details

A code injection vulnerability exists in DedeCMS's plus/mytag_js.php file where the aid parameter is not properly sanitized before processing. An unauthenticated attacker can send a crafted request over the network to inject arbitrary code that will be executed server-side, resulting in remote code execution.

Affected products

  • DedeCMS DedeCMS up to 5.7.118

Timeline

  • 2026-09-20: disclosed

References

Related threats