Yunucms is a content management system with a focused but more prominent-than-typical vulnerability footprint, where disclosures center on its core product and cluster around web application input-handling weaknesses. The recurring vulnerabilities span cross-site scripting, code injection, and path traversal flaws that are characteristic of CMS platforms with user-supplied content and file-management features, and the exposure carries a meaningful tendency toward serious severity. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yunucms over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19180CRITICAL statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.p | Nov 11, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-19181HIGH statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated b | Nov 11, 2018 | 7.5 | 24 | NO | NO |
CVE-2019-5310MEDIUM YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST reques | Jan 4, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-17322MEDIUM Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter. | Sep 22, 2018 | 6.1 | 22 | NO | NO |
CVE-2019-5311MEDIUM An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS vulnerability via the index.php/index/show/index cw parameter. | Jan 4, 2019 | 6.1 | 21 | NO | NO |
CVE-2020-18446MEDIUM Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php. | Aug 12, 2021 | 4.8 | 18 | NO | NO |
CVE-2018-18726MEDIUM An XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5. | Oct 29, 2018 | 4.8 | 18 | NO | NO |
CVE-2018-18725MEDIUM An XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5. | Oct 29, 2018 | 4.8 | 18 | NO | NO |
CVE-2018-18724MEDIUM An XSS issue was discovered in index.php/admin/category/editcategory?id=73 in YUNUCMS 1.1.5. | Oct 29, 2018 | 4.8 | 18 | NO | NO |
CVE-2018-18723MEDIUM An XSS issue was discovered in index.php/admin/area/editarea/id/110000 in YUNUCMS 1.1.5. | Oct 29, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yunucms.
Media articles that mention a CVE ID that affects a product developed by Yunucms — matched by CVE ID, not by vendor name.