CVE-2025-11136
- EPSS 0.05%
- Veröffentlicht 29.09.2025 03:15:42
- Zuletzt bearbeitet 11.12.2025 18:35:46
A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted upload. The...
CVE-2025-9400
- EPSS 0.05%
- Veröffentlicht 25.08.2025 00:32:06
- Zuletzt bearbeitet 11.12.2025 18:45:55
A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This manipulation of the argument File causes unrestricted upload. Remote exploitation of the attack is poss...
CVE-2025-9399
- EPSS 0.04%
- Veröffentlicht 25.08.2025 00:02:05
- Zuletzt bearbeitet 11.12.2025 18:47:07
A vulnerability was detected in YiFang CMS up to 2.0.5. Affected by this issue is some unknown functionality of the file app/logic/L_tool.php. The manipulation of the argument new_url results in sql injection. The attack may be launched remotely. The...
CVE-2025-9398
- EPSS 0.04%
- Veröffentlicht 24.08.2025 23:32:06
- Zuletzt bearbeitet 11.12.2025 18:53:20
A security vulnerability has been detected in YiFang CMS up to 2.0.5. Affected by this vulnerability is the function exportInstallTable of the file app/utils/base/database/Migrate.php. The manipulation leads to information disclosure. The attack may ...
CVE-2025-5383
- EPSS 0.03%
- Veröffentlicht 31.05.2025 15:15:20
- Zuletzt bearbeitet 09.06.2025 19:00:27
A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Article Management Module. The manipulation of the argument Default Value leads to cross site scr...
CVE-2025-5381
- EPSS 0.23%
- Veröffentlicht 31.05.2025 14:31:10
- Zuletzt bearbeitet 09.06.2025 19:00:14
A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/File/downloadFile of the component Admin Panel. The manipulation of the argument File leads to path trav...
CVE-2025-45887
- EPSS 0.06%
- Veröffentlicht 09.05.2025 00:00:00
- Zuletzt bearbeitet 12.06.2025 16:39:34
Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.