VYPR

YFCMF

by YFCMF

CVEs (5)

  • CVE-2020-23691CriMay 14, 2021
    risk 0.64cvss 9.8epss 0.03

    YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.

  • CVE-2018-16431HigSep 4, 2018
    risk 0.57cvss 8.8epss 0.01

    admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account.

  • CVE-2020-23689MedMay 14, 2021
    risk 0.31cvss 4.8epss 0.01

    In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page.

  • CVE-2023-3057MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in YFCMF up to 3.0.4. It has been rated as problematic. This issue affects some unknown processing of the file app/admin/controller/Ajax.php. The manipulation of the argument controllername leads to path traversal: '../filedir'. The attack may be…

  • CVE-2023-3056MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in YFCMF up to 3.0.4. It has been declared as problematic. This vulnerability affects unknown code of the file index.php. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the…