{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dedecms--5.7.118/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-94004"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DedeCMS (\u003c= 5.7.118)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["DedeCMS"],"content_html":"\u003cp\u003eDedeCMS versions up to and including 5.7.118 are vulnerable to a remote code injection flaw located in the 'plus/mytag_js.php' file. The vulnerability stems from improper input validation of the 'aid' argument, which allows an unauthenticated attacker to inject and execute arbitrary code on the target server. Because the vulnerability is reachable via standard HTTP GET requests to the identified file, it poses a high risk to installations of the affected content management system. Proof-of-concept exploit code has been publicly disclosed, increasing the likelihood of opportunistic exploitation by threat actors. Organizations hosting DedeCMS should verify their version and restrict access to the 'plus/mytag_js.php' endpoint or apply vendor-provided patches.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in unauthenticated remote code execution (RCE) on the web server hosting DedeCMS. This allows an attacker to gain full control over the application, access sensitive database information, exfiltrate user data, or use the compromised server as a pivot point for further lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize the identification of all internet-facing DedeCMS instances in the environment.\u003c/li\u003e\n\u003cli\u003eUpgrade all DedeCMS installations to a version beyond 5.7.118 immediately.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to block HTTP requests to '/plus/mytag_js.php' containing suspicious characters (e.g., shell metacharacters or alphanumeric strings designed to trigger code execution) in the 'aid' parameter.\u003c/li\u003e\n\u003cli\u003eReview web server logs for HTTP requests targeting the 'plus/mytag_js.php' file with unusual values in the query string to identify attempted exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-20T12:21:13Z","date_published":"2026-09-20T12:21:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dedecms-code-injection/","summary":"DedeCMS versions up to 5.7.118 contain a code injection vulnerability in the plus/mytag_js.php file that allows unauthenticated remote attackers to execute arbitrary code via the aid argument.","title":"Remote Code Injection Vulnerability in DedeCMS","url":"https://feed.craftedsignal.io/briefs/2026-09-dedecms-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - DedeCMS (\u003c= 5.7.118)","version":"https://jsonfeed.org/version/1.1"}