yzmcms CVE Vulnerabilities & Metrics

Focus on yzmcms vulnerabilities and metrics.

Last updated: 16 Apr 2025, 22:25 UTC

About yzmcms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with yzmcms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total yzmcms CVEs: 42
Earliest CVE date: 26 Feb 2018, 03:29 UTC
Latest CVE date: 08 Apr 2025, 02:15 UTC

Latest CVE reference: CVE-2025-3397

Rolling Stats

30-day Count (Rolling): 1
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -75.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -75.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical yzmcms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.21

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 18
4.0-6.9 23
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS yzmcms CVEs

These are the five CVEs with the highest CVSS scores for yzmcms, sorted by severity first and recency.

All CVEs for yzmcms

CVE-2025-3397 yzmcms vulnerability CVSS: 5.0 08 Apr 2025, 02:15 UTC

A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument gourl leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-24291 yzmcms vulnerability CVSS: 0 06 Feb 2024, 16:15 UTC

An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.

CVE-2023-52274 yzmcms vulnerability CVSS: 0 11 Jan 2024, 03:15 UTC

member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.

CVE-2020-23595 yzmcms vulnerability CVSS: 0 11 Aug 2023, 14:15 UTC

Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.

CVE-2020-20502 yzmcms vulnerability CVSS: 0 20 Jun 2023, 15:15 UTC

Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.

CVE-2021-36712 yzmcms vulnerability CVSS: 0 03 Feb 2023, 18:15 UTC

Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function.

CVE-2022-23383 yzmcms vulnerability CVSS: 6.4 10 Mar 2022, 17:45 UTC

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

CVE-2022-23384 yzmcms vulnerability CVSS: 6.8 15 Feb 2022, 13:15 UTC

YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add

CVE-2022-23889 yzmcms vulnerability CVSS: 5.0 28 Jan 2022, 21:15 UTC

The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.

CVE-2022-23888 yzmcms vulnerability CVSS: 6.8 28 Jan 2022, 21:15 UTC

YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.

CVE-2022-23887 yzmcms vulnerability CVSS: 4.3 28 Jan 2022, 21:15 UTC

YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.

CVE-2020-19951 yzmcms vulnerability CVSS: 6.8 23 Sep 2021, 20:15 UTC

A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.

CVE-2020-19950 yzmcms vulnerability CVSS: 3.5 23 Sep 2021, 20:15 UTC

A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-19949 yzmcms vulnerability CVSS: 3.5 23 Sep 2021, 20:15 UTC

A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-20341 yzmcms vulnerability CVSS: 5.0 01 Sep 2021, 20:15 UTC

YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.

CVE-2020-19118 yzmcms vulnerability CVSS: 3.5 30 Jul 2021, 14:15 UTC

Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.

CVE-2020-35972 yzmcms vulnerability CVSS: 4.3 03 Jun 2021, 21:15 UTC

An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.

CVE-2020-35971 yzmcms vulnerability CVSS: 3.5 03 Jun 2021, 21:15 UTC

A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.

CVE-2020-35970 yzmcms vulnerability CVSS: 5.0 03 Jun 2021, 21:15 UTC

An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.

CVE-2020-23370 yzmcms vulnerability CVSS: 3.5 10 May 2021, 23:15 UTC

In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.

CVE-2020-23369 yzmcms vulnerability CVSS: 4.3 10 May 2021, 23:15 UTC

In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.

CVE-2020-18084 yzmcms vulnerability CVSS: 4.3 30 Apr 2021, 21:15 UTC

Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in.

CVE-2020-22394 yzmcms vulnerability CVSS: 4.3 19 Nov 2020, 18:15 UTC

In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.

CVE-2019-16532 yzmcms vulnerability CVSS: 5.8 26 Sep 2019, 16:15 UTC

An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.

CVE-2019-16678 yzmcms vulnerability CVSS: 4.3 21 Sep 2019, 20:15 UTC

admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.

CVE-2018-16247 yzmcms vulnerability CVSS: 3.5 20 Jun 2019, 16:15 UTC

YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter.

CVE-2019-9661 yzmcms vulnerability CVSS: 3.5 11 Mar 2019, 05:29 UTC

Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter,

CVE-2019-9660 yzmcms vulnerability CVSS: 3.5 11 Mar 2019, 05:29 UTC

Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.

CVE-2019-9570 yzmcms vulnerability CVSS: 3.5 05 Mar 2019, 14:29 UTC

An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.

CVE-2018-20015 yzmcms vulnerability CVSS: 6.8 10 Dec 2018, 09:29 UTC

YzmCMS v5.2 has admin/role/add.html CSRF.

CVE-2018-19849 yzmcms vulnerability CVSS: 3.5 04 Dec 2018, 09:29 UTC

An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter.

CVE-2018-19092 yzmcms vulnerability CVSS: 4.3 07 Nov 2018, 19:29 UTC

An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie.

CVE-2018-17044 yzmcms vulnerability CVSS: 3.5 14 Sep 2018, 07:29 UTC

In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.

CVE-2018-11554 yzmcms vulnerability CVSS: 7.5 05 Jun 2018, 11:29 UTC

The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attackers to hijack accounts via a brute-force approach.

CVE-2018-10224 yzmcms vulnerability CVSS: 6.0 19 Apr 2018, 08:29 UTC

An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.

CVE-2018-10223 yzmcms vulnerability CVSS: 6.0 19 Apr 2018, 08:29 UTC

An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.

CVE-2018-10026 yzmcms vulnerability CVSS: 3.5 11 Apr 2018, 18:29 UTC

The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.

CVE-2018-8756 yzmcms vulnerability CVSS: 6.5 18 Mar 2018, 06:29 UTC

Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in the POST data of an index.php?m=member&c=member_content&a=init request.

CVE-2018-8078 yzmcms vulnerability CVSS: 3.5 13 Mar 2018, 08:29 UTC

YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html.

CVE-2018-7653 yzmcms vulnerability CVSS: 4.3 04 Mar 2018, 19:29 UTC

In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.

CVE-2018-7579 yzmcms vulnerability CVSS: 6.5 01 Mar 2018, 19:29 UTC

\application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html.

CVE-2018-7479 yzmcms vulnerability CVSS: 5.0 26 Feb 2018, 03:29 UTC

YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.