๐Ÿ” CVE Alert

CVE-2026-19353

MEDIUM 5.0

DedeCMS Installation Wizard index.php _4_Setup file inclusion

CVSS Score
5.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used.

CWE CWE-73
Vendor n/a
Product dedecms
Published Aug 9, 2026
Stay Ahead of the Next One

Get instant alerts for n/a dedecms

Be the first to know when new medium vulnerabilities affecting n/a dedecms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / DedeCMS
5.7.118 UTF8SP2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/387207 vuldb.com: https://vuldb.com/vuln/387207/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19353 vuldb.com: https://vuldb.com/submit/865977 github.com: https://github.com/I4m6da/CVE/issues/9

Credits

๐Ÿ” I4m6da (VulDB User)