CVE-2026-30694: Code Injection
Published Mar 19, 2026
·Updated
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the arrayfilter component
Affected Software
2 affected components
DedeCMS Dedecms<=5.7.118
DedeCMS Dedecms<=5.7.118
Event History
Mar 19, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30694?
CVE-2026-30694 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2026-30694?
To fix CVE-2026-30694, upgrade DedeCMS to version 5.7.119 or later.
3
What software is affected by CVE-2026-30694?
CVE-2026-30694 affects DedeCMS versions 5.7.118 and earlier.
4
Can CVE-2026-30694 be exploited remotely?
Yes, CVE-2026-30694 can be exploited remotely by an attacker to execute arbitrary code.
5
What components are involved in the exploitation of CVE-2026-30694?
The exploitation of CVE-2026-30694 involves the array_filter component within DedeCMS.