---
id: CVE-2026-94004
title: A vulnerability was found in DedeCMS up to 5.7.118
summary: >-
  A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an
  unknown function of the file plus/mytag_js.php. The manipulation of the
  argument aid results in code injection. The attack can be launched remotely.
  The explo…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-94
product: DedeCMS
affected:
  - DedeCMS 5.7.118
published: '2026-09-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:19:18.553'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94004'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-94004'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/944743'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407953'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407953/cti'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/944743'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T16:46:14.361925Z'
epss: 0.00516
epssPercentile: 0.41403
ingestedAt: '2026-09-20T12:21:05.901Z'
---

## Overview

A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument aid results in code injection. The attack can be launched remotely. The exploit has been made public and could be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
