yunucms CVE 脆弱性と CVE 一覧(15)

製品(CPE): — CVE 件数: 15

yunucms 脆弱性概要

yunucms 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

過去の問題は主に vendor risk cross-site scripting and パス処理の欠陥 などに関し、一部は ファイル上書き を招き、vendor surface production workloads and vendor surface software deployment 関連の場面に影響します。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 115 / 15 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2020-18446 Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php. [email protected] 4.8 0.53% 2021-08-12 2026-06-16
CVE-2020-18445 Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php. [email protected] 6.1 0.72% 2021-08-12 2026-06-16
CVE-2019-5311 An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS vulnerability via the index.php/index/show/index cw parameter. [email protected] 6.1 0.68% 2019-01-04 2026-06-16
CVE-2019-5310 YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST request. [email protected] 6.1 0.68% 2019-01-04 2026-06-16
CVE-2018-19181 statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file. [email protected] 7.5 1.45% 2018-11-11 2026-06-16
CVE-2018-19180 statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php. [email protected] 9.8 1.51% 2018-11-11 2026-06-16
CVE-2018-18726 An XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5. [email protected] 4.8 0.56% 2018-10-29 2026-06-16
CVE-2018-18725 An XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5. [email protected] 4.8 0.56% 2018-10-29 2026-06-16
CVE-2018-18724 An XSS issue was discovered in index.php/admin/category/editcategory?id=73 in YUNUCMS 1.1.5. [email protected] 4.8 0.56% 2018-10-29 2026-06-16
CVE-2018-18723 An XSS issue was discovered in index.php/admin/area/editarea/id/110000 in YUNUCMS 1.1.5. [email protected] 4.8 0.56% 2018-10-29 2026-06-16
CVE-2018-18722 An XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5. [email protected] 4.8 0.56% 2018-10-29 2026-06-16
CVE-2018-18721 An XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5. [email protected] 4.8 0.56% 2018-10-29 2026-06-16
CVE-2018-18720 An XSS issue was discovered in index.php/admin/system/basic in YUNUCMS 1.1.5. [email protected] 4.8 0.56% 2018-10-29 2026-06-16
CVE-2018-17322 Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter. [email protected] 6.1 0.76% 2018-09-21 2026-06-16
CVE-2018-9993 YUNUCMS 1.0.7 has XSS via the content title on an admin/content/addcontent/cid/## page (aka a news center page). [email protected] 4.8 0.53% 2018-04-10 2026-06-16
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence