CVE detail
CVE-2026-19353
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 5
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://vuldb.com/vuln/387207/ctivuldb.com
No excerpt available.
Exploitvuldb.comAug 9, 2026, 1:16 PM - https://vuldb.com/vuln/387207vuldb.com
No excerpt available.
Exploitvuldb.comAug 9, 2026, 1:16 PM - https://vuldb.com/submit/865977vuldb.com
No excerpt available.
Exploitvuldb.comAug 9, 2026, 1:16 PM - https://vuldb.com/cve/CVE-2026-19353vuldb.com
No excerpt available.
Exploitvuldb.comAug 9, 2026, 1:16 PM - https://github.com/I4m6da/CVE/issues/9github.com
No excerpt available.
Exploitgithub.comAug 9, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-72842CVSS 9.4 · Critical
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authoriza…
- CVE-2026-72841CVSS 9.4 · Critical
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outsi…
- CVE-2026-17482CVSS 9.8 · Critical
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
- CVE-2026-45725CVSS 7.1 · High
compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HT…
- CVE-2026-16987CVSS 8.8 · High
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
- CVE-2026-16898CVSS 7.8 · High
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.