Yccms is a content management system whose vulnerability profile concentrates around its core product and centers on common web-application input-handling flaws, including path traversal, cross-site scripting, SQL injection, and unrestricted file uploads. These weakness classes reflect the risks inherent to CMS platforms that accept and process user input for content management and file storage. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yccms over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-20287CRITICAL Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution. | Feb 1, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-20289CRITICAL Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability. | Feb 1, 2021 | 9.8 | 28 | NO | NO |
CVE-2025-64048MEDIUM YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within t | Nov 24, 2025 | 6.1 | 24 | NO | NO |
CVE-2020-20290HIGH Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper judgment of the request parameters, triggers a directory trave | Feb 1, 2021 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yccms.
Media articles that mention a CVE ID that affects a product developed by Yccms — matched by CVE ID, not by vendor name.