Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Yunucms Subscribe
Filtered by product Yunucms
Total 15 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-18446 1 Yunucms 1 Yunucms 2021-08-13 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.
CVE-2020-18445 1 Yunucms 1 Yunucms 2021-08-13 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.
CVE-2019-5311 1 Yunucms 1 Yunucms 2019-01-10 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS vulnerability via the index.php/index/show/index cw parameter.
CVE-2019-5310 1 Yunucms 1 Yunucms 2019-01-10 4.3 MEDIUM 6.1 MEDIUM
YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST request.
CVE-2018-19180 1 Yunucms 1 Yunucms 2018-12-12 7.5 HIGH 9.8 CRITICAL
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.
CVE-2018-19181 1 Yunucms 1 Yunucms 2018-12-12 6.4 MEDIUM 7.5 HIGH
statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file.
CVE-2018-18720 1 Yunucms 1 Yunucms 2018-12-04 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in index.php/admin/system/basic in YUNUCMS 1.1.5.
CVE-2018-18721 1 Yunucms 1 Yunucms 2018-12-04 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5.
CVE-2018-18722 1 Yunucms 1 Yunucms 2018-12-04 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5.
CVE-2018-18723 1 Yunucms 1 Yunucms 2018-12-04 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in index.php/admin/area/editarea/id/110000 in YUNUCMS 1.1.5.
CVE-2018-18724 1 Yunucms 1 Yunucms 2018-12-04 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in index.php/admin/category/editcategory?id=73 in YUNUCMS 1.1.5.
CVE-2018-18725 1 Yunucms 1 Yunucms 2018-12-04 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5.
CVE-2018-18726 1 Yunucms 1 Yunucms 2018-12-04 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5.
CVE-2018-17322 1 Yunucms 1 Yunucms 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter.
CVE-2018-9993 1 Yunucms 1 Yunucms 2018-05-16 3.5 LOW 4.8 MEDIUM
YUNUCMS 1.0.7 has XSS via the content title on an admin/content/addcontent/cid/## page (aka a news center page).