VYPR

Yzmcms

by Yzmcms

Source repositories

CVEs (49)

  • CVE-2019-9660MedMar 11, 2019
    risk 0.31cvss 4.8epss 0.01

    Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.

  • CVE-2019-9570MedMar 5, 2019
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.

  • CVE-2018-19849MedDec 4, 2018
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter.

  • CVE-2018-17044MedSep 14, 2018
    risk 0.31cvss 4.8epss 0.01

    In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.

  • CVE-2018-10026MedApr 11, 2018
    risk 0.31cvss 4.8epss 0.01

    The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.

  • CVE-2025-3397MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument gourl leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to…

  • CVE-2020-35972MedJun 3, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.

  • CVE-2026-15202MedJul 9, 2026
    risk 0.00cvss 4.3epss 0.00

    A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzmphp.php of the component Header Handler. The manipulation of the argument HTTP_HOST leads to cross site scripting. The attack may be initiated remotely. The…

  • CVE-2026-13529MedJun 29, 2026
    risk 0.00cvss 5.6epss 0.00

    A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl can lead to sql injection. The attack can be executed remotely. A high complexity level is associated…

Page 3 of 3