


Perceptive Security
SOC/SIEM Consultancy

An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
Published:
31 March 2026 at 22:00:00
Alert date:
1 April 2026 at 20:03:08
Source:
nvd.nist.gov
Web Technologies
A code execution vulnerability has been discovered in DedeCMS version 5.7.118. The vulnerability allows attackers to execute arbitrary code through crafted setup tag values during module upload processes. This represents a critical security flaw in the content management system that could lead to complete system compromise. Attackers can exploit this vulnerability by uploading malicious modules with specially crafted setup tags. The vulnerability affects the module upload functionality of the CMS. This could allow unauthorized code execution on affected systems running the vulnerable DedeCMS version.
Technical details
Mitigation steps:
Affected products:
DedeCMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30643
https://gist.github.com/0psPwn/10c43912adee9bfe2ff4fec947d4ee5a
https://www.dedecms.com/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
