CVE-2022-23384
- EPSS 0.13%
- Veröffentlicht 15.02.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:29
YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add
CVE-2022-23889
- EPSS 0.29%
- Veröffentlicht 28.01.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:49:25
The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.
CVE-2022-23888
- EPSS 0.45%
- Veröffentlicht 28.01.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:49:25
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
CVE-2022-23887
- EPSS 0.23%
- Veröffentlicht 28.01.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:49:24
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.
CVE-2020-19951
- EPSS 0.17%
- Veröffentlicht 23.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:30
A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.
CVE-2020-19950
- EPSS 0.32%
- Veröffentlicht 23.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:30
A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
CVE-2020-19949
- EPSS 0.32%
- Veröffentlicht 23.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:29
A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
CVE-2020-20341
- EPSS 0.43%
- Veröffentlicht 01.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:01
YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
CVE-2020-19118
- EPSS 0.24%
- Veröffentlicht 30.07.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:08:57
Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
CVE-2020-35972
- EPSS 0.14%
- Veröffentlicht 03.06.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:28:36
An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.