CVE-2026-94004: DedeCMS mytag_js.php code injection
A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytagjs.php. The manipulation of the argument aid results in code injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for investigation?
DedeCMS deployments running versions up to 5.7.118 should be prioritized, particularly instances reachable remotely. The vulnerable functionality is in plus/mytag_js.php.
What does an attacker need to exploit this issue?
The issue can be exploited remotely by manipulating the aid argument sent to plus/mytag_js.php. No privileges or user interaction are indicated in the provided severity vector.
Is public exploitation information available?
Yes. The exploit has been made public and could be used, increasing the urgency of reviewing exposed affected installations.
How can defenders check whether they may be affected?
Identify the installed DedeCMS version and determine whether it is 5.7.118 or earlier. Also review whether plus/mytag_js.php is present and remotely accessible, and inspect relevant requests for suspicious aid argument manipulation.