CVE-2026-30643: Code Injection
Published Apr 1, 2026
·Updated
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7.118
Event History
Apr 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:28 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30643?
CVE-2026-30643 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2026-30643?
To fix CVE-2026-30643, update DedeCMS to a version later than 5.7.118.
3
What type of attack does CVE-2026-30643 facilitate?
CVE-2026-30643 allows attackers to execute arbitrary code via crafted input during module uploads.
4
Which versions of DedeCMS are affected by CVE-2026-30643?
DedeCMS versions up to and including 5.7.118 are affected by CVE-2026-30643.
5
Is CVE-2026-30643 specific to any modules in DedeCMS?
CVE-2026-30643 can be exploited through crafted setup tag values in any module upload.