Lucene search

K

Yzncms Security Vulnerabilities

cve
cve

CVE-2023-37131

A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request.

6.5CVSS

6.5AI Score

0.001EPSS

2023-07-06 03:15 PM
94
cve
cve

CVE-2023-43233

A stored cross-site scripting (XSS) vulnerability in the cms/content/edit component of YZNCMS v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.

6.1CVSS

5.8AI Score

0.001EPSS

2023-09-27 11:15 PM
28
cve
cve

CVE-2024-42939

A cross-site scripting (XSS) vulnerability in the component /index/index.html of YZNCMS v1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the configured remarks text field.

5.4CVSS

5.6AI Score

0.0004EPSS

2024-08-21 05:15 AM
23