What is CVE-2026-19353?
A file inclusion vulnerability has been identified in DedeCMS versions up to 5.7.118 UTF8SP2, specifically within the _4_Setup function of the install/index.php file in the Installation Wizard component. This vulnerability can be exploited remotely, potentially leading to arbitrary code execution. Users are advised to update DedeCMS to the latest version.
Azərbaycanca: DedeCMS-in 5.7.118 UTF8SP2 və daha əvvəlki versiyalarında, quraşdırma sihirbazının install/index.php faylındakı _4_Setup funksiyasında fayl daxiletmə (file inclusion) zəifliyi aşkarlanıb. Bu zəiflik uzaqdan kod icrasına imkan verə bilər. İstifadəçilərə DedeCMS-i ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of DedeCMS are affected by CVE-2026-19353?
This vulnerability affects DedeCMS versions up to 5.7.118 UTF8SP2.
In which component and file is CVE-2026-19353 located?
The vulnerability is located in the _4_Setup function of the install/index.php file within the Installation Wizard component.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.