CVE-2026-19353
DedeCMS Installation Wizard index.php _4_Setup file inclusion
CVSS Score
5.0
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used.
| CWE | CWE-73 |
| Vendor | n/a |
| Product | dedecms |
| Published | Aug 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a dedecms
Be the first to know when new medium vulnerabilities affecting n/a dedecms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / DedeCMS
5.7.118 UTF8SP2
References
Credits
๐ I4m6da (VulDB User)