Yifang
Vendor:
First CVE: Feb 22, 2026 · Active for under a year
6
Total CVEs
More Total CVEs than 83% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
5.1
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Yifang over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 2026
5 months ago
Most Recent CVE
Mar 8, 2026
142 days ago
CVE Severity & Scoring
Yifang6 CVEs
100%
All CVEs353,173 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required6 (100.0%)
Privileges Required
Low3 (50.0%)
High3 (50.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3741MEDIUM A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argu | Mar 8, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-2934MEDIUM A security vulnerability has been detected in YiFang CMS up to 2.0.5. This impacts the function update of the file app/db/admin/D_friendLinkGroup.php of the component Extended Mana | Feb 22, 2026 | 4.8 | 19 | NO | NO |
CVE-2026-3743MEDIUM A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.php. Executing a manipulation of the argument Name can lead t | Mar 8, 2026 | 5.4 | 18 | NO | NO |
CVE-2026-3742MEDIUM A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of the argument T | Mar 8, 2026 | 5.4 | 18 | NO | NO |
CVE-2026-2933MEDIUM A weakness has been identified in YiFang CMS up to 2.0.5. This affects the function update of the file app/db/admin/D_adManage.php of the component Extended Management Module. Exec | Feb 22, 2026 | 4.8 | 17 | NO | NO |
CVE-2026-2932MEDIUM A security flaw has been discovered in YiFang CMS up to 2.0.5. The impacted element is the function update of the file app/db/admin/D_adPosition.php of the component Extended Manag | Feb 22, 2026 | 4.8 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Yifang
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.5 | 3 | 5.4 | 0.2% | 0 | 0 |