Yeager is a content management system vendor with a modestly represented vulnerability footprint centered on its Yeager CMS product. The recurring exposure reflects application-layer weaknesses including SQL injection, server-side request forgery, and unrestricted file upload, which are characteristic of web-facing CMS platforms and underscore the importance of input validation and file-handling controls. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yeager over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7567CRITICAL SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter. | Feb 18, 2020 | 9.8 | 35 | NO | YES |
CVE-2015-7568CRITICAL SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parame | Apr 24, 2017 | 9.8 | 35 | NO | YES |
CVE-2015-7571HIGH Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. | Aug 7, 2017 | 7.8 | 34 | NO | YES |
CVE-2015-7569HIGH SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter. | Apr 24, 2017 | 8.8 | 32 | NO | YES |
CVE-2015-7570HIGH Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost paramete | Apr 24, 2017 | 7.2 | 29 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yeager.
Media articles that mention a CVE ID that affects a product developed by Yeager — matched by CVE ID, not by vendor name.