CVE-2026-19353Disclosure

LOWCVSS 1.3 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-09)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-08: 1Mentions · 2026-08-09: 2Technical Details · 2026-08-08: 1Technical Details · 2026-08-09: 108-0808-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-081
Disclosure1
2026-08-092
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19353 A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installa… https://www.cve.org/CVERecord?id=CVE-2026-19353 ----- Traducción: CVE-2026-19353 Se … http://infoflow.cloud`

    Post summary

    The post announces the discovery of CVE-2026-19353 in DedeCMS, detailing the affected component but offering no PoC, exploit code, or patch information.

    0000027
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19353 A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installa… https://www.cve.org/CVERecord?id=CVE-2026-19353

    Post summary

    A new vulnerability (CVE-2026-19353) in DedeCMS up to 5.7.118 has been announced, specifying the affected function and file, but no PoC, exploit, active use, patch, or technical details are provided.

    000001.9K
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🚨 New DedeCMS file-inclusion vulnerability disclosed CVE-2026-19353 affects DedeCMS through version 5.7.118. The issue is located in the installation wizard and involves unsafe handling of the _4_Setup parameter, resulting in file inclusion. 📅 Disclosed: August 8. 🔎 Source: CVE/Vulnerability feed via YANAC. #DedeCMS #WebSecurity #CVE #CyberSecurity

    Post summary

    A new file‑inclusion vulnerability (CVE-2026-19353) was disclosed for DedeCMS up to version 5.7.118, involving the unsafe handling of the '_4_Setup' parameter. No PoC, exploit code, or patch information is provided.

    0000040
    34 followersView on X

Explore more