Xyhcms is a niche content management system with a focused vulnerability profile centered on web-application input handling. The recurring weaknesses—cross-site request forgery and cross-site scripting—reflect the typical attack surface of browser-facing CMS platforms where user input processing and session management are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xyhcms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14583HIGH xyhai.php?s=/Auth/addUser in XYHCMS 3.5 allows CSRF to add a background administrator account. | Jul 24, 2018 | 8.8 | 25 | NO | NO |
CVE-2018-10127HIGH An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addition of an account with the administrator role. | Apr 16, 2018 | 8.8 | 22 | NO | NO |
CVE-2020-21656MEDIUM XYHCMS v3.6 contains a stored cross-site scripting (XSS) vulnerability in the component xyhai.php?s=/Link/index. | Oct 6, 2021 | 5.4 | 20 | NO | NO |
CVE-2018-10128MEDIUM An issue was discovered in XYHCMS 3.5. It has XSS via the test parameter to index.php. | Apr 16, 2018 | 6.1 | 20 | NO | NO |
CVE-2020-20586MEDIUM A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the na | Jul 8, 2021 | 4.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xyhcms.
Media articles that mention a CVE ID that affects a product developed by Xyhcms — matched by CVE ID, not by vendor name.