Vendor
DedeCMS versions up to 5.7.118 contain a code injection vulnerability in the plus/mytag_js.php file that allows unauthenticated remote attackers to execute arbitrary code via the aid argument.