Yuba's vulnerability footprint centers on the U5 CMS, a narrowly scoped but prominently deployed web content management platform. The vendor's disclosures cluster around application-layer input-handling and request-validation weaknesses, including cross-site scripting, cross-site request forgery, path traversal, and SQL injection, which are characteristic of web application attack surfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yuba over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1578MEDIUM Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) pidve | Feb 11, 2015 | 5.8 | 32 | NO | YES |
CVE-2022-32444MEDIUM An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php. | Jun 17, 2022 | 6.1 | 31 | NO | YES |
CVE-2022-34937HIGH Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code. | Aug 3, 2022 | 8.8 | 28 | NO | NO |
CVE-2015-1577MEDIUM Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to arbitrary files via a (1) .. (dot dot) or (2) full pathname in | Feb 11, 2015 | 6.4 | 28 | NO | YES |
CVE-2015-1576HIGH Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) | Feb 11, 2015 | 7.5 | 28 | NO | YES |
CVE-2015-1575MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web script or HTML via the (1) c, (2) i, (3) l, or (4) p parame | Feb 11, 2015 | 4.3 | 22 | NO | YES |
CVE-2022-32442MEDIUM u5cms version 8.3.5 is vulnerable to Cross Site Scripting (XSS). When a user accesses the default home page if the parameter passed in is http://127.0.0.1/? "Onmouseover=%27tzgl (9 | Jun 17, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yuba.
Media articles that mention a CVE ID that affects a product developed by Yuba — matched by CVE ID, not by vendor name.