Yifang Vulnerabilities

Security vulnerability tracking for Yifangcms Yifang

Last updated: Mar 8, 2026
Total CVEs

6

Critical

0

With Exploits

6

Last 30 Days

0

Vulnerability Timeline

6 vulnerabilities discovered over time for Yifang

Severity Distribution

Critical0
0%
High0
0%
Medium6
100%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2026-37435.1

An attacker can exploit a vulnerability in YiFang CMS to inject malicious scripts into web pages, potentially allowing them to steal sensitive information from users who visit those pages. This can be done remotely by manipulating a specific input field, and the issue is already known and can be actively exploited.

yifangcmsyifang
Exploit Available
about 1 month agoMar 8, 2026
CVE-2026-37425.1

This vulnerability allows an attacker to inject malicious scripts into a web page, which can then execute in the browsers of users visiting that page, potentially stealing their information or performing actions on their behalf. The attacker can exploit this remotely by manipulating a specific input field in the YiFang CMS software, and the issue is already public, meaning it could be exploited by anyone without needing special access.

yifangcmsyifang
Exploit Available
about 1 month agoMar 8, 2026
CVE-2026-37415.1

An attacker can inject malicious scripts into a website using a vulnerability in YiFang CMS, allowing them to execute harmful code in the browsers of users who visit the affected site. This can be done remotely by manipulating a specific input field, and since the vendor has not responded to the issue, it remains a risk for users of the software.

yifangcmsyifang
Exploit Available
about 1 month agoMar 8, 2026
CVE-2026-29344.8

An attacker can inject malicious scripts into a web page through a vulnerable part of the YiFang CMS, allowing them to execute harmful actions on users' browsers. This vulnerability affects versions up to 2.0.5 and can be exploited remotely without needing to be on the same network.

yifangcmsyifang
Exploit Available
about 1 month agoFeb 22, 2026
CVE-2026-29334.8

An attacker can inject malicious scripts into the YiFang CMS, allowing them to execute harmful actions in the context of a user's browser. This vulnerability can be exploited remotely by manipulating a specific input field in the system's management module, and the exploit is publicly available.

yifangcmsyifang
Exploit Available
about 1 month agoFeb 22, 2026
CVE-2026-29324.8

An attacker can use this vulnerability to inject malicious scripts into a web page viewed by other users, potentially stealing their information or performing actions on their behalf. This can be done remotely by manipulating specific input fields in the YiFang CMS software, which is vulnerable in versions up to 2.0.5.

yifangcmsyifang
Exploit Available
about 1 month agoFeb 22, 2026

About Yifangcms Yifang Security

This page provides comprehensive security vulnerability tracking for Yifangcms Yifang. Our database includes all CVEs affecting this product, updated in real-time from official sources.

Each vulnerability listing includes detailed CVSS severity analysis, exploit availability status, AI-generated explanations, and direct links to official security patches and vendor advisories.

Security Recommendations

  • • Always keep Yifang updated to the latest version
  • • Subscribe to security advisories from Yifangcms
  • • Monitor this page for new vulnerabilities affecting your version
  • • Prioritize patching critical and high severity issues immediately