References https://nvd.nist.gov/vuln/detail/CVE-2025-6335 https://cve.imfht.com/detail/CVE-2025-6335 https://cve.imfht.com/detail/CVE-2025-6335?lang=en https://github.com/advisories/GHSA-qgg2-ph52-84j3 https://vuldb.com/vuln/313331 https://github.com/jujubooom/CVE-2025-6335 https://www.cnblogs.com/ljbguanli/p/19136561 https://github.com/jujubooom/CVE-2025-6335/issues/1 https://ewoji.cn/2025/06/20/CVE-2025-6335-dedeCMS%E5%90%8E%E5%8F%B0%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5RCE/
Related VulnerabilitiesPoCCVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerPoCCVE-2026-16268: Newsletters < 4.16 - Unauthenticated SSRF via SNS Bounce HandlerPoCCVE-2026-42461: Arcane < 1.18.0 - Unauthenticated Template and Env DisclosureArcane /api/templates 未授权访问漏洞(CVE-2026-42461)PoCCVE-2026-28496: FOSSBilling - Server-Side Template Injection深科特LEANMES /Handler/PrintUpdcate.ashx 信息泄露漏洞智邦国际ERP /SYSN/json/pcclient/GetAllPrintTemplate.ashx SQL 注入漏洞索贝 template/api/styleList/3 未授权访问漏洞中成科信票务管理平台 /LoginHandler.ashx 存在SQL注入漏洞WordPress WP Responsive Images /wp-responsive-images/image_handler.php 文件读取漏洞(CVE-2026-1557)博硕控制系统接口ComboBoxAjaxHandler存在sql注入博硕工程拌和站智能管理平台 /ComboBoxAjaxHandler.ashx SQL 注入漏洞方天云ERP /GRReport/GRHandler.ashx SQL 注入漏洞