Yzmcms
by Yzmcms
Source repositories
CVEs (49)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-39174 | Med | 0.40 | 6.1 | 0.00 | Jul 5, 2024 | A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article. | ||
| CVE-2024-24291 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2024 | An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL. | ||
| CVE-2023-52274 | Med | 0.40 | 6.1 | 0.00 | Jan 11, 2024 | member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header. | ||
| CVE-2020-23369 | Med | 0.40 | 6.1 | 0.01 | May 10, 2021 | In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3. | ||
| CVE-2020-18084 | Med | 0.40 | 6.1 | 0.01 | Apr 30, 2021 | Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in. | ||
| CVE-2020-22394 | Med | 0.40 | 6.1 | 0.01 | Nov 19, 2020 | In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability. | ||
| CVE-2019-16532 | Med | 0.40 | 6.1 | 0.01 | Sep 26, 2019 | An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections. | ||
| CVE-2018-19092 | Med | 0.40 | 6.1 | 0.01 | Nov 7, 2018 | An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie. | ||
| CVE-2024-35110 | Med | 0.36 | 5.5 | 0.00 | May 17, 2024 | A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker. | ||
| CVE-2021-36712 | Med | 0.35 | 5.4 | 0.00 | Feb 3, 2023 | Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function. | ||
| CVE-2022-23889 | Med | 0.35 | 5.3 | 0.01 | Jan 28, 2022 | The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments. | ||
| CVE-2020-19118 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2021 | Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html. | ||
| CVE-2020-35971 | Med | 0.35 | 5.4 | 0.01 | Jun 3, 2021 | A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page. | ||
| CVE-2020-23370 | Med | 0.35 | 5.4 | 0.01 | May 10, 2021 | In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML. | ||
| CVE-2018-16247 | Med | 0.35 | 5.4 | 0.01 | Jun 20, 2019 | YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter. | ||
| CVE-2018-8078 | Med | 0.35 | 5.4 | 0.01 | Mar 13, 2018 | YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html. | ||
| CVE-2018-7479 | Med | 0.35 | 5.3 | 0.02 | Feb 26, 2018 | YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php. | ||
| CVE-2020-19950 | Med | 0.31 | 4.8 | 0.01 | Sep 23, 2021 | A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML. | ||
| CVE-2020-19949 | Med | 0.31 | 4.8 | 0.01 | Sep 23, 2021 | A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML. | ||
| CVE-2019-9661 | Med | 0.31 | 4.8 | 0.01 | Mar 11, 2019 | Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter, |
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.
- risk 0.40cvss 6.1epss 0.00
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
- risk 0.40cvss 6.1epss 0.00
member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.
- risk 0.40cvss 6.1epss 0.01
In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in.
- risk 0.40cvss 6.1epss 0.01
In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.
- risk 0.40cvss 6.1epss 0.01
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie.
- risk 0.36cvss 5.5epss 0.00
A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.
- risk 0.35cvss 5.4epss 0.00
Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function.
- risk 0.35cvss 5.3epss 0.01
The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
- risk 0.35cvss 5.4epss 0.01
A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.
- risk 0.35cvss 5.4epss 0.01
In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.
- risk 0.35cvss 5.4epss 0.01
YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter.
- risk 0.35cvss 5.4epss 0.01
YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html.
- risk 0.35cvss 5.3epss 0.02
YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.
- risk 0.31cvss 4.8epss 0.01
A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
- risk 0.31cvss 4.8epss 0.01
A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
- risk 0.31cvss 4.8epss 0.01
Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter,
Page 2 of 3