← Back

Yunucms

yunucms

Vendor: Yunucms • 15 CVEs

CVEs (15)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yunucms
1Yunucms
Nov 21, 2024
Aug 12, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.
1Yunucms
1Yunucms
Nov 21, 2024
Aug 12, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.
1Yunucms
1Yunucms
Nov 21, 2024
Jan 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS vulnerability via the index.php/index/show/index cw parameter.
1Yunucms
1Yunucms
Nov 21, 2024
Jan 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST request.
1Yunucms
1Yunucms
Nov 21, 2024
Nov 11, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete th...Show more
statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file.Show less
1Yunucms
1Yunucms
Nov 21, 2024
Nov 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX fiel...Show more
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.Show less
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in index.php/admin/category/editcategory?id=73 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in index.php/admin/area/editarea/id/110000 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in index.php/admin/system/basic in YUNUCMS 1.1.5.
1Yunucms
1Yunucms
Nov 21, 2024
Sep 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter.
1Yunucms
1Yunucms
Nov 21, 2024
Apr 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
YUNUCMS 1.0.7 has XSS via the content title on an admin/content/addcontent/cid/## page (aka a news center page).