CVE-2020-27533 EXPLOIT
5.4
MEDIUM · CVSS 3.1 · EPSS 3.6% (pctl 89)
Patch early
A public exploit exists.
Description
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
Scoring
| CVSS | 5.4 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 3.56% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-10-22 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| dedecms | dedecms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | DedeCMS v.5.8 - _keyword_ Cross-Site Scripting | 2020-10-30 |
References
→ the Explorer · watch your stack · NVD