Yzmcms
by Yzmcms
Source repositories
CVEs (49)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9660 | Med | 0.31 | 4.8 | 0.01 | Mar 11, 2019 | Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter. | ||
| CVE-2019-9570 | Med | 0.31 | 4.8 | 0.01 | Mar 5, 2019 | An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter. | ||
| CVE-2018-19849 | Med | 0.31 | 4.8 | 0.00 | Dec 4, 2018 | An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter. | ||
| CVE-2018-17044 | Med | 0.31 | 4.8 | 0.01 | Sep 14, 2018 | In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter. | ||
| CVE-2018-10026 | Med | 0.31 | 4.8 | 0.01 | Apr 11, 2018 | The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php. | ||
| CVE-2025-3397 | Med | 0.28 | 4.3 | 0.01 | Apr 8, 2025 | A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument gourl leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to… | ||
| CVE-2020-35972 | Med | 0.28 | 4.3 | 0.01 | Jun 3, 2021 | An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html. | ||
| CVE-2026-15202 | Med | 0.00 | 4.3 | 0.00 | Jul 9, 2026 | A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzmphp.php of the component Header Handler. The manipulation of the argument HTTP_HOST leads to cross site scripting. The attack may be initiated remotely. The… | ||
| CVE-2026-13529 | Med | 0.00 | 5.6 | 0.00 | Jun 29, 2026 | A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl can lead to sql injection. The attack can be executed remotely. A high complexity level is associated… |
- risk 0.31cvss 4.8epss 0.01
Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.
- risk 0.31cvss 4.8epss 0.00
An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter.
- risk 0.31cvss 4.8epss 0.01
In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.
- risk 0.31cvss 4.8epss 0.01
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
- risk 0.28cvss 4.3epss 0.01
A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument gourl leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to…
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.
- risk 0.00cvss 4.3epss 0.00
A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzmphp.php of the component Header Handler. The manipulation of the argument HTTP_HOST leads to cross site scripting. The attack may be initiated remotely. The…
- risk 0.00cvss 5.6epss 0.00
A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl can lead to sql injection. The attack can be executed remotely. A high complexity level is associated…
Page 3 of 3