An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component
References
| Link | Resource |
|---|---|
| https://jacobjacobjacob.gitbook.io/cve-2026-30694/ | Exploit Mitigation Third Party Advisory |
| https://leixyous-personal-organization.gitbook.io/dedecms-file-manage-getshell-via-bypass-blacklist/ | Exploit Mitigation Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-19 18:16
Updated : 2026-03-25 21:11
NVD link : CVE-2026-30694
Mitre link : CVE-2026-30694
CVE.ORG link : CVE-2026-30694
JSON object : View
Products Affected
dedecms
- dedecms
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
