CVE-2026-15533: DedeCMS Column Management search.php code injection
A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a manipulation of the argument Column Name results in code injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15533?
CVE-2026-15533 has a medium severity rating of 4.7.
What type of vulnerability is CVE-2026-15533?
CVE-2026-15533 is classified as a code injection vulnerability.
How does the CVE-2026-15533 vulnerability occur?
CVE-2026-15533 occurs due to the manipulation of the argument Column Name in the /plus/search.php file of DedeCMS.
What impact does CVE-2026-15533 pose?
CVE-2026-15533 can allow remote attackers to inject code into the DedeCMS application.
How can I mitigate CVE-2026-15533?
To mitigate CVE-2026-15533, ensure that you sanitize and validate all user inputs in the affected components.