CVE-2026-15533
A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column
CVSS
4.7
Medium
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Published: Jul 13, 2026 · Last modified: Jul 13, 2026 · CWE-74 · CWE-94
0.2%EPSS · 30 days0.2%
2026-07-132026-07-20
A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a manipulation of the argument Column Name results in code injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
- github.comhttps://github.com/DunkBoyZz/cve/blob/cb7d6aa088d5ae4b603399af0a3279c18b084f11/DedeCMS%20V5.7.118%20Column%20Name%20Cache%20File%20Writing%20RCE%20Vulnerability.docx
- vuldb.comhttps://vuldb.com/cve/CVE-2026-15533
- vuldb.comhttps://vuldb.com/submit/854988
- vuldb.comhttps://vuldb.com/submit/854989
- vuldb.comhttps://vuldb.com/vuln/377878
- vuldb.comhttps://vuldb.com/vuln/377878/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32489.8 CRI100.0%
KEV—80Langflow Missing Authentication Vulnerability6dCVE-2026-341978.8 HIG99.9%
KEV—80Apache ActiveMQ Improper Input Validation Vulnerability6dCVE-2026-154107.2 HIG71.2%
KEV—71SonicWall SMA1000 Appliances Code Injection Vulnerability5dCVE-2025-670389.8 CRI55.4%
KEV—67Lantronix EDS5000 Code Injection Vulnerability14dCVE-2021-416539.8 CRI99.5%
——30The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.12dCVE-2026-222007.5 HIG99.4%
——30Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.6d