Vulnerabilities (CVE)

Filtered by vendor Yccms Subscribe
Filtered by product Yccms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-20287 1 Yccms 1 Yccms 2021-02-04 7.5 HIGH 9.8 CRITICAL
Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.
CVE-2020-20289 1 Yccms 1 Yccms 2021-02-03 7.5 HIGH 9.8 CRITICAL
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.