Yzmcms
Products
2- 49 CVEs
- 1 CVE
Recent CVEs
50| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11554 | Cri | 0.64 | 9.8 | 0.01 | Jun 5, 2018 | The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attackers to hijack accounts… | ||
| CVE-2022-23383 | Cri | 0.59 | 9.1 | 0.01 | Mar 10, 2022 | YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home… | ||
| CVE-2020-23595 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2023 | Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint. | ||
| CVE-2022-23384 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add | ||
| CVE-2022-23888 | Hig | 0.57 | 8.8 | 0.01 | Jan 28, 2022 | YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html. | ||
| CVE-2020-19951 | Hig | 0.57 | 8.8 | 0.01 | Sep 23, 2021 | A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application. | ||
| CVE-2018-20015 | Hig | 0.57 | 8.8 | 0.01 | Dec 10, 2018 | YzmCMS v5.2 has admin/role/add.html CSRF. | ||
| CVE-2020-20341 | Hig | 0.49 | 7.5 | 0.01 | Sep 1, 2021 | YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function. | ||
| CVE-2020-35970 | Hig | 0.49 | 7.5 | 0.01 | Jun 3, 2021 | An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read. | ||
| CVE-2019-8411 | Hig | 0.49 | 7.5 | 0.03 | Feb 17, 2019 | admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=../ directory traversal. | ||
| CVE-2018-8756 | Hig | 0.47 | 7.2 | 0.03 | Mar 18, 2018 | Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in the POST data of an index.php?m=member&c=member_content&a=init request. | ||
| CVE-2018-7579 | Hig | 0.47 | 7.2 | 0.01 | Mar 1, 2018 | \application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html. | ||
| CVE-2024-28725 | Hig | 0.46 | 7.1 | 0.00 | May 6, 2024 | Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings. | ||
| CVE-2018-10224 | Med | 0.44 | 6.8 | 0.01 | Apr 19, 2018 | An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html. | ||
| CVE-2018-10223 | Med | 0.44 | 6.8 | 0.01 | Apr 19, 2018 | An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html. | ||
| CVE-2018-7653 | Med | 0.43 | 6.1 | 0.08 | Mar 4, 2018 | In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter. | ||
| CVE-2020-20502 | Med | 0.42 | 6.5 | 0.00 | Jun 20, 2023 | Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function. | ||
| CVE-2022-23887 | Med | 0.42 | 6.5 | 0.01 | Jan 28, 2022 | YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete. | ||
| CVE-2019-16678 | Med | 0.42 | 6.5 | 0.01 | Sep 21, 2019 | admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route. | ||
| CVE-2026-29933 | Med | 0.40 | 6.1 | 0.00 | Mar 26, 2026 | A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referrer value in the request header. |
- risk 0.64cvss 9.8epss 0.01
The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attackers to hijack accounts…
- risk 0.59cvss 9.1epss 0.01
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home…
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.
- risk 0.57cvss 8.8epss 0.01
YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add
- risk 0.57cvss 8.8epss 0.01
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.
- risk 0.57cvss 8.8epss 0.01
YzmCMS v5.2 has admin/role/add.html CSRF.
- risk 0.49cvss 7.5epss 0.01
YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.
- risk 0.49cvss 7.5epss 0.03
admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=../ directory traversal.
- risk 0.47cvss 7.2epss 0.03
Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in the POST data of an index.php?m=member&c=member_content&a=init request.
- risk 0.47cvss 7.2epss 0.01
\application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html.
- risk 0.46cvss 7.1epss 0.00
Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.
- risk 0.44cvss 6.8epss 0.01
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.
- risk 0.44cvss 6.8epss 0.01
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.
- risk 0.43cvss 6.1epss 0.08
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
- risk 0.42cvss 6.5epss 0.00
Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.
- risk 0.42cvss 6.5epss 0.01
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.
- risk 0.42cvss 6.5epss 0.01
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
- risk 0.40cvss 6.1epss 0.00
A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referrer value in the request header.