Lucene search

K

Youdiancms Security Vulnerabilities

cve
cve

CVE-2020-18116

A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.

8.8CVSS

9.1AI Score

0.001EPSS

2021-08-27 09:15 PM
23
6
cve
cve

CVE-2022-32299

YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/SiteAction.class.php.

8.8CVSS

8.9AI Score

0.001EPSS

2022-06-15 05:15 PM
42
2
cve
cve

CVE-2022-32300

YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Action/Admin/MailAction.class.php.

8.8CVSS

9AI Score

0.001EPSS

2022-06-15 05:15 PM
62
3
cve
cve

CVE-2022-32301

YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php.

9.8CVSS

9.8AI Score

0.002EPSS

2022-06-15 05:15 PM
34
3
cve
cve

CVE-2024-3117

A vulnerability classified as critical was found in YouDianCMS up to 9.5.12. This vulnerability affects unknown code of the file App\Lib\Action\Admin\ChannelAction.class.php. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has be...

4.7CVSS

6.9AI Score

0.0004EPSS

2024-03-31 02:15 AM
26
cve
cve

CVE-2024-7328

A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown processing of the file /t.php?action=phpinfo. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public an...

5.3CVSS

5.1AI Score

0.003EPSS

2024-07-31 11:15 PM
24
cve
cve

CVE-2024-7329

A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/multiimage/dialogs/image_upload.php. The manipulation of the argument files leads to unrestricted upload. It is possible to launch the attack remotely. ...

9.8CVSS

6.4AI Score

0.004EPSS

2024-07-31 11:15 PM
26
cve
cve

CVE-2024-7330

A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/Core/Extend/Function/ydLib.php. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The ex...

6.3CVSS

6.5AI Score

0.002EPSS

2024-08-01 12:15 AM
24