[VulDB]( entry style (entry metadata → description → affected products
| `README.md` | The advisory itself, VulDB-style layout |
| `vuldb.json` | The same entry in machine-readable form |
| `poc/` | Non-weaponised proof-of-concept scripts |
| `evidence/` | Reproduction screenshots |
These documents serve as the **public reference** required by CVE (MITRE) and VulDB when
| Product | Vulnerability | CWE | CVSS v3.1 | Disclosure | Advisory |
| DedeCMS V5.7.118 | `dede/update_guide.php` code injection (RCE) | CWE-94, CWE-96, CWE-352 | 7.2 / 8.8 | 2026-09-25 | [link](DedeCMS/V5.7.118-update_guide-RCE/) |
All content is published for defensive, identification and educational purposes. Proofs of
concept are non-weaponised and must only be used against systems you own or are explicitly
authorized to test. The author accepts no liability for misuse.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
