CVE-2025-56304: XSS
Published Sep 23, 2025
·Updated
Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.
Affected Software
2 affected components
YzmCMS YzmCMS<=7.3
YzmCMS YzmCMS<=7.3
Event History
Sep 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56304?
CVE-2025-56304 is considered a medium severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-56304?
To fix CVE-2025-56304, update YzmCMS to version 7.4 or later which addresses the vulnerability.
3
What types of attacks can CVE-2025-56304 facilitate?
CVE-2025-56304 can facilitate cross-site scripting attacks, potentially allowing attackers to execute scripts in the context of users' browsers.
4
Which versions of YzmCMS are affected by CVE-2025-56304?
CVE-2025-56304 affects YzmCMS versions up to and including 7.3.
5
Where does CVE-2025-56304 manifest in YzmCMS?
CVE-2025-56304 manifests through the referer header in the register page of YzmCMS.