Y
YzmCMS
Security Risk Profile
40
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 50 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 26, 2018 to present
50
Total CVEs
13
Critical+High
0
Exploited
13
Unpatched
Threat Assessment
Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
13
Critical/High
Risk Level
40/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
2High
11Medium
35Low
2Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
3Age Distribution
Common Weaknesses (CWE)
1
XSS
26
2
CSRF
11
3
SQL Injection
3
4
Code Injection
2
5
SSRF
2
Most Affected Products
1. YzmCMS YzmCMS56
Recent Vulnerabilities
See more →CVE-2026-105156
CVSS 2.9low
YzmCMS MD5 system.func.php password weak password hash
Oct 4, 2026🔧 No Patch
CVE-2026-75417
CVSS 7.2high
Aug 27, 2026🔧 No Patch
CVE-2026-13529
CVSS 2.9low
YzmCMS index.php sql injection
Jun 29, 2026🔧 No Patch
CVE-2026-29933
CVSS 6.1medium
Mar 26, 2026🔧 No Patch
CVE-2025-56304
CVSS 6.1medium
Sep 23, 2025🔧 No Patch
CVE-2025-3397
CVSS 6.1EPSS 0%medium
YzmCMS message.tpl cross site scripting
Apr 8, 2025🔧 No Patch
CVE-2024-39174
CVSS 6.1medium
Jul 5, 2024🔧 No Patch
CVE-2024-35110
CVSS 5.5medium
May 17, 2024🔧 No Patch
CVE-2024-28725
CVSS 7.1EPSS 0%high
May 6, 2024🔧 No Patch
CVE-2024-24291
CVSS 6.1EPSS 0%medium
Feb 6, 2024🔧 No Patch
Monitor YzmCMS in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.