yzncms CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

yzncms vulnerability overview

Aggregates CVE and security vulnerability intelligence across all yzncms-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk csrf, with potential vendor impact session compromise across vendor surface production workloads and vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-25791 An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file. [email protected] 4.4 0.12% 2025-02-26 2025-04-07
CVE-2024-42939 A cross-site scripting (XSS) vulnerability in the component /index/index.html of YZNCMS v1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the configured remarks text field. [email protected] 5.4 0.25% 2024-08-21 2024-08-31
CVE-2023-43233 A stored cross-site scripting (XSS) vulnerability in the cms/content/edit component of YZNCMS v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter. [email protected] 6.1 0.20% 2023-09-27 2024-11-21
CVE-2023-37131 A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request. [email protected] 6.5 0.06% 2023-07-06 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence