CVE-2025-25791
- EPSS 0.02%
- Veröffentlicht 26.02.2025 15:15:27
- Zuletzt bearbeitet 07.04.2025 18:52:59
An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.
CVE-2024-42939
- EPSS 0.16%
- Veröffentlicht 21.08.2024 05:15:14
- Zuletzt bearbeitet 31.08.2024 02:58:34
A cross-site scripting (XSS) vulnerability in the component /index/index.html of YZNCMS v1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the configured remarks text field.
CVE-2023-43233
- EPSS 0.2%
- Veröffentlicht 27.09.2023 23:15:12
- Zuletzt bearbeitet 21.11.2024 08:23:51
A stored cross-site scripting (XSS) vulnerability in the cms/content/edit component of YZNCMS v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.
CVE-2023-37131
- EPSS 0.05%
- Veröffentlicht 06.07.2023 15:15:16
- Zuletzt bearbeitet 21.11.2024 08:11:03
A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request.