Yzmcms

Yzmcms

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.19%
  • Veröffentlicht 04.10.2026 12:30:10
  • Zuletzt bearbeitet 06.10.2026 15:04:52

A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient...

  • EPSS 0.29%
  • Veröffentlicht 27.08.2026 00:00:00
  • Zuletzt bearbeitet 03.09.2026 17:59:00

A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET(...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 09.07.2026 17:30:07
  • Zuletzt bearbeitet 09.07.2026 19:17:04

A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzmphp.php of the component Header Handler. The manipulation of the argument HTTP_HOST leads to cross site scripting. The attack may ...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 29.06.2026 03:00:08
  • Zuletzt bearbeitet 29.06.2026 18:46:31

A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl can lead to sql injection. The attack can be executed remotely. A high c...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 26.03.2026 15:16:35
  • Zuletzt bearbeitet 31.03.2026 21:38:24

A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referrer value in the request header.

  • EPSS 0.19%
  • Veröffentlicht 23.09.2025 17:15:33
  • Zuletzt bearbeitet 05.07.2026 02:16:59

Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 08.04.2025 01:31:07
  • Zuletzt bearbeitet 09.04.2025 14:37:11

A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument gourl leads to cross site scripting. It is possible to launch the attack remotely. The e...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 05.07.2024 18:15:32
  • Zuletzt bearbeitet 13.06.2025 14:40:01

A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 17.05.2024 08:15:06
  • Zuletzt bearbeitet 10.06.2025 18:32:58

A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 06.05.2024 21:15:48
  • Zuletzt bearbeitet 10.06.2025 19:42:27

Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.