DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in membertoadmin.php.
DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/codo.php via the dopost, rpok, and aid parameters.
DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /filemanageview.php?fmdo=edit&filename.