Yifangcms operates a narrowly scoped content-management system where the durable signal centers on application-layer input-handling weaknesses, particularly code injection and cross-site scripting vulnerabilities arising from insufficient input neutralization. These weakness classes are characteristic of web applications handling user-supplied content without sufficient validation and encoding safeguards. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yifangcms over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3741MEDIUM A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argu | Mar 8, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-2934MEDIUM A security vulnerability has been detected in YiFang CMS up to 2.0.5. This impacts the function update of the file app/db/admin/D_friendLinkGroup.php of the component Extended Mana | Feb 22, 2026 | 4.8 | 19 | NO | NO |
CVE-2026-3743MEDIUM A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.php. Executing a manipulation of the argument Name can lead t | Mar 8, 2026 | 5.4 | 18 | NO | NO |
CVE-2026-3742MEDIUM A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of the argument T | Mar 8, 2026 | 5.4 | 18 | NO | NO |
CVE-2026-2933MEDIUM A weakness has been identified in YiFang CMS up to 2.0.5. This affects the function update of the file app/db/admin/D_adManage.php of the component Extended Management Module. Exec | Feb 22, 2026 | 4.8 | 17 | NO | NO |
CVE-2026-2932MEDIUM A security flaw has been discovered in YiFang CMS up to 2.0.5. The impacted element is the function update of the file app/db/admin/D_adPosition.php of the component Extended Manag | Feb 22, 2026 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yifangcms.
Media articles that mention a CVE ID that affects a product developed by Yifangcms — matched by CVE ID, not by vendor name.