Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown

CVE-2020-19950

Disclosure Date: September 23, 2021 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
Attacker Value
Unknown

CVE-2020-19949

Disclosure Date: September 23, 2021 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
Attacker Value
Unknown

CVE-2020-19951

Disclosure Date: September 23, 2021 (last updated February 23, 2025)
A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.
Attacker Value
Unknown

CVE-2020-20341

Disclosure Date: September 01, 2021 (last updated February 23, 2025)
YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
Attacker Value
Unknown

CVE-2020-19118

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
Attacker Value
Unknown

CVE-2020-35970

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.
Attacker Value
Unknown

CVE-2020-35972

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.
Attacker Value
Unknown

CVE-2020-35971

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.
Attacker Value
Unknown

CVE-2020-23370

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.
Attacker Value
Unknown

CVE-2020-23369

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.