Products: 1
Vulnerabilities: 50
Known Exploited: 0
2
Critical Level Threats
11
High Level Threats
37
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-75417
A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization. This allows an authenticated administrator to execute arbitrary SQL queries via boolean-based blind injection, potentially leading to full database compromise.
Last Modified: Aug 28, 2026
Published: Aug 27, 2026
CVE-2026-15202
YzmCMS Header yzmphp.php get_url cross site scripting
Last Modified: Jul 09, 2026
Published: Jul 09, 2026
CVE-2026-13529
YzmCMS index.php sql injection
Last Modified: Jun 29, 2026
Published: Jun 29, 2026
CVE-2026-29933
YZMCMS v7.4 Reflected XSS via Modified Referrer Header
Last Modified: Apr 02, 2026
Published: Mar 26, 2026
CVE-2025-56304
Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.
Last Modified: Oct 08, 2025
Published: Sep 23, 2025
Items Per Page
