CVE-2026-76783: DeDeCMS advancedsearch.php sql injection
A security vulnerability has been detected in DeDeCMS 531UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction, according to the supplied vector. Systems exposing the affected advanced search endpoint are the relevant attack surface.
What is the potential impact?
Successful exploitation may affect confidentiality, integrity, and availability at low impact levels. The issue is classified as SQL injection and has a high severity score of 7.3.
How urgent is remediation?
A public exploit has been disclosed and may be used. Prioritize investigation and remediation for deployments of DeDeCMS 53_1_UTF8, particularly where /plus/advancedsearch.php is reachable remotely.