Yfcmf is a narrowly scoped vendor with a focused product line, where the observed vulnerability signal concentrates on web application input-handling and request-validation weaknesses, notably cross-site scripting and cross-site request forgery. These classes reflect the parser and session-management attack surface typical of web-facing applications; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yfcmf over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-23691CRITICAL YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php. | May 14, 2021 | 9.8 | 29 | NO | NO |
CVE-2018-16431HIGH admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account. | Sep 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2020-23689MEDIUM In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page. | May 14, 2021 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yfcmf.
Media articles that mention a CVE ID that affects a product developed by Yfcmf — matched by CVE ID, not by vendor name.