yunucms CVE Vulnerabilities & Metrics

Focus on yunucms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About yunucms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with yunucms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total yunucms CVEs: 15
Earliest CVE date: 10 Apr 2018, 21:29 UTC
Latest CVE date: 12 Aug 2021, 17:15 UTC

Latest CVE reference: CVE-2020-18446

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical yunucms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.17

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 5
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS yunucms CVEs

These are the five CVEs with the highest CVSS scores for yunucms, sorted by severity first and recency.

All CVEs for yunucms

CVE-2020-18446 yunucms vulnerability CVSS: 3.5 12 Aug 2021, 17:15 UTC

Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.

CVE-2020-18445 yunucms vulnerability CVSS: 4.3 12 Aug 2021, 17:15 UTC

Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.

CVE-2019-5311 yunucms vulnerability CVSS: 4.3 04 Jan 2019, 15:29 UTC

An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS vulnerability via the index.php/index/show/index cw parameter.

CVE-2019-5310 yunucms vulnerability CVSS: 4.3 04 Jan 2019, 14:29 UTC

YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST request.

CVE-2018-19181 yunucms vulnerability CVSS: 6.4 11 Nov 2018, 17:29 UTC

statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file.

CVE-2018-19180 yunucms vulnerability CVSS: 7.5 11 Nov 2018, 17:29 UTC

statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.

CVE-2018-18726 yunucms vulnerability CVSS: 3.5 29 Oct 2018, 12:29 UTC

An XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5.

CVE-2018-18725 yunucms vulnerability CVSS: 3.5 29 Oct 2018, 12:29 UTC

An XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5.

CVE-2018-18724 yunucms vulnerability CVSS: 3.5 29 Oct 2018, 12:29 UTC

An XSS issue was discovered in index.php/admin/category/editcategory?id=73 in YUNUCMS 1.1.5.

CVE-2018-18723 yunucms vulnerability CVSS: 3.5 29 Oct 2018, 12:29 UTC

An XSS issue was discovered in index.php/admin/area/editarea/id/110000 in YUNUCMS 1.1.5.

CVE-2018-18722 yunucms vulnerability CVSS: 3.5 29 Oct 2018, 12:29 UTC

An XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5.

CVE-2018-18721 yunucms vulnerability CVSS: 3.5 29 Oct 2018, 12:29 UTC

An XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5.

CVE-2018-18720 yunucms vulnerability CVSS: 3.5 29 Oct 2018, 12:29 UTC

An XSS issue was discovered in index.php/admin/system/basic in YUNUCMS 1.1.5.

CVE-2018-17322 yunucms vulnerability CVSS: 4.3 22 Sep 2018, 02:29 UTC

Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter.

CVE-2018-9993 yunucms vulnerability CVSS: 3.5 10 Apr 2018, 21:29 UTC

YUNUCMS 1.0.7 has XSS via the content title on an admin/content/addcontent/cid/## page (aka a news center page).