Yxcms is a content management system that exhibits a vulnerability profile centered on web-application security flaws, including cross-site request forgery, code injection, cross-site scripting, and improper permission controls. These weaknesses are characteristic of the input handling and authorization demands placed on CMS platforms that manage user-generated content and administrative functions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yxcms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19404HIGH In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by creating a ZIP archive containing a con | Nov 21, 2018 | 7.2 | 23 | NO | NO |
CVE-2018-8761HIGH protected\apps\member\controller\shopcarController.php in Yxcms building system (compatible cell phone) v1.4.7 has a logic flaw allowing attackers to modify a price, before form su | Mar 19, 2018 | 7.5 | 23 | NO | NO |
CVE-2018-11003MEDIUM An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controller/adminController.php allows remote attackers to delete adm | May 12, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-8805MEDIUM Yxcms building system (compatible cell phone) v1.4.7 has XSS via the content parameter to protected\apps\default\view\default\extend_guestbook.php or protected\apps\default\view\mo | Mar 20, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-13025MEDIUM protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via the index.php?r=admin/photo/delpic picname parameter. | Jun 29, 2018 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yxcms.
Media articles that mention a CVE ID that affects a product developed by Yxcms — matched by CVE ID, not by vendor name.