{"id":"CVE-2026-94004","published":"2026-09-20T12:17:05.593","lastModified":"2026-09-21T17:19:18.553","description":"A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument aid results in code injection. The attack can be launched remotely. The exploit has been made public and could be used.","cvssScore":7.3,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-74","CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://vuldb.com/cve/CVE-2026-94004","tags":[]},{"url":"https://vuldb.com/submit/944743","tags":[]},{"url":"https://vuldb.com/vuln/407953","tags":[]},{"url":"https://vuldb.com/vuln/407953/cti","tags":[]},{"url":"https://vuldb.com/submit/944743","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}