Wanglongcn operates a focused product line centered on the Yifang application, where vulnerabilities cluster around access control, file handling, and code injection mechanisms. The vendor's disclosures skew toward serious outcomes, with an elevated tendency toward critical severity, and recur across weakness classes including improper access control, unrestricted file uploads, sensitive information exposure, code injection, and path traversal that collectively suggest insufficient input validation and authorization enforcement throughout the application layer. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wanglongcn over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9400HIGH A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This manipulation of the argument File | Aug 25, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-9399HIGH A vulnerability was detected in YiFang CMS up to 2.0.5. Affected by this issue is some unknown functionality of the file app/logic/L_tool.php. The manipulation of the argument new_ | Aug 25, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-9398HIGH A security vulnerability has been detected in YiFang CMS up to 2.0.5. Affected by this vulnerability is the function exportInstallTable of the file app/utils/base/database/Migrate. | Aug 25, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-45887CRITICAL Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent. | May 9, 2025 | 9.1 | 24 | NO | NO |
CVE-2025-11136HIGH A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipu | Sep 29, 2025 | 7.2 | 23 | NO | NO |
CVE-2025-5381HIGH A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/File/downloadFile of the component | May 31, 2025 | 7.2 | 21 | NO | NO |
CVE-2025-5383MEDIUM A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Article Management Module. | May 31, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wanglongcn.
Media articles that mention a CVE ID that affects a product developed by Wanglongcn — matched by CVE ID, not by vendor name.