


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument …
Published:
1 June 2026 at 22:00:00
Alert date:
2 June 2026 at 21:03:34
Source:
nvd.nist.gov
Web Technologies
A critical SQL injection vulnerability has been discovered in DedeCMS version 5.7.88. The flaw affects the RemoveXSS function in the /plus/carbuyaction.php file, where manipulation of the postname/des arguments leads to SQL injection. The vulnerability can be exploited remotely and poses a significant security risk. Public exploits have been released, making this an actively exploitable threat. Organizations using DedeCMS should prioritize patching this vulnerability immediately.
Technical details
Mitigation steps:
Affected products:
DedeCMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10608
https://vuldb.com/cve/CVE-2026-10608
https://vuldb.com/submit/829415
https://vuldb.com/vuln/367915
https://vuldb.com/vuln/367915/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
