Yzmcms is a content management system with a modest vulnerability footprint concentrated in a single product line. The recurring exposure centers on web-application input-handling and access-control weaknesses, particularly cross-site scripting, cross-site request forgery, code injection, server-side request forgery, and exposure of resources to unintended scopes—a pattern typical of server-side web frameworks where input validation and output encoding demand careful implementation. Despite the vendor's representation among tracked entities, the majority of its disclosed vulnerabilities do not reach critical severity and the overall profile does not indicate a recurring pattern of widespread exploitation or public tooling development. Defenders deploying this CMS should prioritize input validation and CSRF protections and monitor the vendor's security advisories for application-layer flaws; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yzmcms over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7653MEDIUM In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter. | Mar 4, 2018 | 6.1 | 43 | NO | YES |
CVE-2018-11554CRITICAL The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long | Jun 5, 2018 | 9.8 | 30 | NO | NO |
CVE-2022-23383CRITICAL YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login sta | Mar 10, 2022 | 9.1 | 29 | NO | NO |
CVE-2020-19951HIGH A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application. | Sep 23, 2021 | 8.8 | 27 | NO | NO |
CVE-2018-20015HIGH YzmCMS v5.2 has admin/role/add.html CSRF. | Dec 10, 2018 | 8.8 | 27 | NO | NO |
CVE-2022-23384HIGH YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add | Feb 15, 2022 | 8.8 | 26 | NO | NO |
CVE-2020-23595HIGH Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint. | Aug 11, 2023 | 8.8 | 24 | NO | NO |
CVE-2020-20341HIGH YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function. | Sep 1, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-35970HIGH An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read. | Jun 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-8756HIGH Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in the POST data of an index.php?m= | Mar 18, 2018 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yzmcms.
Media articles that mention a CVE ID that affects a product developed by Yzmcms — matched by CVE ID, not by vendor name.