Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yzmcms MEDIUM 6.1
CVE-2026-29933

A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascri…

No fix yet
Fix from $1,600 2026-03-26
Yzmcms MEDIUM 6.1
CVE-2025-56304

Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.

Fix: after 7.3
Fix from $1,600 2025-09-23
Yzmcms MEDIUM 6.1
CVE-2025-3397

A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of …

No fix yet
Fix from $1,600 2025-04-08
Yzmcms MEDIUM 6.1
CVE-2024-39174

A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML v…

No fix yet
Fix from $1,600 2024-07-05
Yzmcms MEDIUM 5.5
CVE-2024-35110

A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users…

No fix yet
Fix from $1,600 2024-05-17
Yzmcms HIGH 7.1
CVE-2024-28725

Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Set…

No fix yet
Fix from $1,950 2024-05-06
Yzmcms MEDIUM 6.1
CVE-2024-24291

An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.

No fix yet
Fix from $1,600 2024-02-06
Yzmcms MEDIUM 6.1
CVE-2023-52274

member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.

Fix: after 7.0
Fix from $1,600 2024-01-11
Yzmcms HIGH 8.8
CVE-2020-23595

Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information …

No fix yet
Fix from $1,950 2023-08-11
Yzmcms MEDIUM 6.5
CVE-2020-20502

Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.

No fix yet
Fix from $1,600 2023-06-20
Yzmcms MEDIUM 5.4
CVE-2021-36712

Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function.

No fix yet
Fix from $1,600 2023-02-03
Yzmcms CRITICAL 9.1
CVE-2022-23383

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessar…

Mitigation only
Fix from $2,300 2022-03-10
Yzmcms HIGH 8.8
CVE-2022-23384

YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add

No fix yet
Fix from $1,950 2022-02-15
Yzmcms HIGH 8.8
CVE-2022-23888

YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.

No fix yet
Fix from $1,950 2022-01-28
Yzmcms MEDIUM 6.5
CVE-2022-23887

YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin…

No fix yet
Fix from $1,600 2022-01-28
Yzmcms MEDIUM 5.3
CVE-2022-23889

The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number …

No fix yet
Fix from $1,600 2022-01-28
Yzmcms HIGH 8.8
CVE-2020-19951

A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.

No fix yet
Fix from $1,950 2021-09-23
Yzmcms HIGH 7.5
CVE-2020-20341

YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.

No fix yet
Fix from $1,950 2021-09-01
Yzmcms MEDIUM 5.4
CVE-2020-19118

Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.

No fix yet
Fix from $1,600 2021-07-30
Yzmcms HIGH 7.5
CVE-2020-35970

An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.

No fix yet
Fix from $1,950 2021-06-03
Yzmcms MEDIUM 5.4
CVE-2020-35971

A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_m…

No fix yet
Fix from $1,600 2021-06-03
Yzmcms MEDIUM 6.1
CVE-2020-23369

In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.

No fix yet
Fix from $1,600 2021-05-10
Yzmcms MEDIUM 5.4
CVE-2020-23370

In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to u…

No fix yet
Fix from $1,600 2021-05-10
Yzmcms MEDIUM 6.1
CVE-2020-18084

Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST …

No fix yet
Fix from $1,600 2021-04-30
Yzmcms MEDIUM 6.1
CVE-2020-22394

In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.

No fix yet
Fix from $1,600 2020-11-19
Yzmcms MEDIUM 6.1
CVE-2019-16532

An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.

No fix yet
Fix from $1,600 2019-09-26
Yzmcms MEDIUM 6.5
CVE-2019-16678

admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.

No fix yet
Fix from $1,600 2019-09-21
Yzmcms MEDIUM 5.4
CVE-2018-16247

YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter.

No fix yet
Fix from $1,600 2019-06-20
Yzmcms HIGH 8.8
CVE-2018-20015

YzmCMS v5.2 has admin/role/add.html CSRF.

No fix yet
Fix from $1,950 2018-12-10
Yzmcms MEDIUM 6.1
CVE-2018-19092

An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pu…

No fix yet
Fix from $1,600 2018-11-07