\application\admin\controller\updateurls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/updateurls/updatecategoryurl.html.
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.