CVE-2025-15004: DedeCMS freelist_main.php sql injection
Published Dec 22, 2025
·Updated
A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelistmain.php. The manipulation of the argument orderby leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
2 affected components
DedeCMS Dedecms<=5.7.118
DedeCMS Dedecms<=5.7.118
Event History
Dec 22, 2025
CVE Published
via MITRE·12:02 AM
Data Sourced
via MITRE·12:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-15004?
CVE-2025-15004 is considered a high severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2025-15004?
To fix CVE-2025-15004, upgrade DedeCMS to the latest version beyond 5.7.118.
3
What type of vulnerability is CVE-2025-15004?
CVE-2025-15004 is an SQL injection vulnerability affecting DedeCMS.
4
Can CVE-2025-15004 be exploited remotely?
Yes, CVE-2025-15004 can be exploited remotely by manipulating the orderby argument.
5
What versions of DedeCMS are affected by CVE-2025-15004?
CVE-2025-15004 affects all versions of DedeCMS up to and including 5.7.118.