Products: 1
    Vulnerabilities: 50
    Known Exploited: 0
    2
    Critical Level Threats
    11
    High Level Threats
    37
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-75417

    A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization. This allows an authenticated administrator to execute arbitrary SQL queries via boolean-based blind injection, potentially leading to full database compromise.

    Last Modified: Aug 28, 2026
    Published: Aug 27, 2026

    CVE-2026-15202

    YzmCMS Header yzmphp.php get_url cross site scripting

    Last Modified: Jul 09, 2026
    Published: Jul 09, 2026

    CVE-2026-13529

    YzmCMS index.php sql injection

    Last Modified: Jun 29, 2026
    Published: Jun 29, 2026

    CVE-2026-29933

    YZMCMS v7.4 Reflected XSS via Modified Referrer Header

    Last Modified: Apr 02, 2026
    Published: Mar 26, 2026

    CVE-2025-56304

    Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.

    Last Modified: Oct 08, 2025
    Published: Sep 23, 2025
    Items Per Page