Xyhcms Project develops a web-based content management system with a narrowly scoped product portfolio, where observed vulnerabilities center on web-application security issues including cross-site request forgery and cross-site scripting. These input-handling and session-validation weaknesses are characteristic of the CMS attack surface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xyhcms Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14583HIGH xyhai.php?s=/Auth/addUser in XYHCMS 3.5 allows CSRF to add a background administrator account. | Jul 24, 2018 | 8.8 | 25 | NO | NO |
CVE-2018-10127HIGH An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addition of an account with the administrator role. | Apr 16, 2018 | 8.8 | 22 | NO | NO |
CVE-2020-21656MEDIUM XYHCMS v3.6 contains a stored cross-site scripting (XSS) vulnerability in the component xyhai.php?s=/Link/index. | Oct 6, 2021 | 5.4 | 20 | NO | NO |
CVE-2018-10128MEDIUM An issue was discovered in XYHCMS 3.5. It has XSS via the test parameter to index.php. | Apr 16, 2018 | 6.1 | 20 | NO | NO |
CVE-2020-20586MEDIUM A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the na | Jul 8, 2021 | 4.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xyhcms Project.
Media articles that mention a CVE ID that affects a product developed by Xyhcms Project — matched by CVE ID, not by vendor name.