YzmCMS vulnerabilities
CVEs whose affected-version data names the YzmCMS package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-105156Low· 3.7A weakness has been identified in YzmCMS up to 7.6
A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with…
▾ Sunlitvia NVD
CVE-2022-23383Critical· 9.1YzmCMS v6.3 is affected by broken access control
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vuln…
▾ Midnightyzmcms · yzmcmsEPSS 1.2%via NVD