SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-51077

HIGH · CVSS 7.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Dede CMS version 5.7.118 is vulnerable to an SQL injection attack through the sqlquery parameter in the sys_sql_query.php component, enabling remote attackers to extract sensitive information from the database. Organizations using this CMS should prioritize patching this vulnerability to mitigate the risk of data breaches. Immediate action is recommended for any entities relying on this version of Dede CMS to safeguard their data integrity and security.

CVE
CVE-2026-51077
Severity
HIGH
CVSS
7.5
EPSS
0.31%

Original NVD Description

SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component