Product
youdiancms
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-3533
CVE-2025-3532
CVE-2025-3531
CVE-2024-57052
CVE-2024-7330
CVE-2024-7329
CVE-2024-7328
CVE-2024-3117
CVE-2022-32301
CVE-2022-32300
CVE-2022-32299
CVE-2020-18116
all versions
A vulnerability, which was classified as problematic, has been found in YouDianCMS 9.5.21. This issue affects some unknown process
all versions
A vulnerability classified as problematic was found in YouDianCMS 9.5.21. This vulnerability affects unknown code of the file /App
all versions
A vulnerability classified as problematic has been found in YouDianCMS 9.5.21. This affects an unknown part of the file /App/Tpl/A
<= 9.5.20
An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the inde
all versions
A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exe
all versions
A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/
all versions
A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown processing o
>= 9.5.0 and <= 9.5.12
A vulnerability classified as critical was found in YouDianCMS up to 9.5.12. This vulnerability affects unknown code of the file A
all versions
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiActi
all versions
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Action/Admin/Ma
all versions
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/SiteAction
all versions
A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.