File Inclusion Vulnerability in DedeCMS Installation Wizard
CVE-2026-19353

2.3LOW

Key Information:

Vendor

DedeCMS

Status
Vendor
CVE Published:
9 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-19353?

A file inclusion vulnerability exists in the Installation Wizard of DedeCMS versions up to 5.7.118 UTF8SP2. This issue arises from the manipulation of the _4_Setup function located in the install/index.php file, potentially allowing an attacker to include arbitrary files remotely. The complexity required to exploit this vulnerability is high, making it challenging for potential attackers to execute. As the details of this exploit are now public, organizations using affected versions of DedeCMS should take immediate action to assess and mitigate their exposure.

Affected Version(s)

DedeCMS 5.7.118 UTF8SP2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

I4m6da (VulDB User)
.