---
id: CVE-2025-11136
title: A flaw has been found in YiFang CMS up to 2.0.2
summary: >-
  A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the
  function webUploader of the file app/app/controller/File.php of the component
  Backend. Executing manipulation of the argument uploadpath can lead to
  unrestricte…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-284
  - CWE-434
vendor: wanglongcn
product: yifang
affected:
  - yifang <= 2.0.2
published: '2025-09-29'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11136'
references:
  - url: >-
      https://github.com/electroN1chahaha/YifangCMS-V2.0.0-Remote-Code-Execution-RCE-/issues/1
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.326213'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.326213'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.657903'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00397
epssPercentile: 0.31816
ingestedAt: '2026-10-09T09:31:00.978Z'
---

## Overview

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.

## Affected

- `yifang <= 2.0.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
