Home/Product/youdiancms
Product

youdiancms

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-3533
all versions
A vulnerability, which was classified as problematic, has been found in YouDianCMS 9.5.21. This issue affects some unknown process
4.3MEDIUM
CVE-2025-3532
all versions
A vulnerability classified as problematic was found in YouDianCMS 9.5.21. This vulnerability affects unknown code of the file /App
4.3MEDIUM
CVE-2025-3531
all versions
A vulnerability classified as problematic has been found in YouDianCMS 9.5.21. This affects an unknown part of the file /App/Tpl/A
4.3MEDIUM
CVE-2024-57052
<= 9.5.20
An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the inde
9.8CRITICAL
CVE-2024-7330
all versions
A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exe
6.3MEDIUM
CVE-2024-7329
all versions
A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/
6.3MEDIUM
CVE-2024-7328
all versions
A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown processing o
5.3MEDIUM
CVE-2024-3117
>= 9.5.0 and <= 9.5.12
A vulnerability classified as critical was found in YouDianCMS up to 9.5.12. This vulnerability affects unknown code of the file A
4.7MEDIUM
CVE-2022-32301
all versions
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiActi
9.8CRITICAL
CVE-2022-32300
all versions
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Action/Admin/Ma
8.8HIGH
CVE-2022-32299
all versions
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/SiteAction
8.8HIGH
CVE-2020-18116
all versions
A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
8.8HIGH
threatengine.sh