Show filters
41 Total Results
Displaying 21-30 of 41
Sort by:
Attacker Value
Unknown

CVE-2020-18084

Disclosure Date: April 30, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in.
Attacker Value
Unknown

CVE-2020-22394

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2019-16532

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
Attacker Value
Unknown

CVE-2019-16678

Disclosure Date: September 21, 2019 (last updated November 27, 2024)
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
Attacker Value
Unknown

CVE-2018-16247

Disclosure Date: June 20, 2019 (last updated November 27, 2024)
YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter.
0
Attacker Value
Unknown

CVE-2019-9660

Disclosure Date: March 11, 2019 (last updated November 27, 2024)
Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.
0
Attacker Value
Unknown

CVE-2019-9661

Disclosure Date: March 11, 2019 (last updated November 27, 2024)
Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter,
0
Attacker Value
Unknown

CVE-2019-9570

Disclosure Date: March 05, 2019 (last updated November 27, 2024)
An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.
0
Attacker Value
Unknown

CVE-2018-20015

Disclosure Date: December 10, 2018 (last updated November 27, 2024)
YzmCMS v5.2 has admin/role/add.html CSRF.
0
Attacker Value
Unknown

CVE-2018-19849

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter.
0