Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Title | DedeCMS flink.php dede_htmlspecialchars sql injection | |
| First Time appeared |
Dedecms
Dedecms dedecms |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dedecms
Dedecms dedecms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-03T14:56:26.817Z
Reserved: 2026-06-02T11:30:13.498Z
Link: CVE-2026-10607
Updated: 2026-06-03T14:55:47.141Z
Status : Deferred
Published: 2026-06-02T20:16:32.020
Modified: 2026-06-04T14:56:49.720
Link: CVE-2026-10607
No data.
OpenCVE Enrichment
Updated: 2026-06-03T04:00:13Z