Filtered by vendor Yfcmf Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-23691 1 Yfcmf 1 Yfcmf 2024-11-21 9.8 Critical
YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.
CVE-2020-23689 1 Yfcmf 1 Yfcmf 2024-11-21 4.8 Medium
In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page.
CVE-2018-16431 1 Yfcmf 1 Yfcmf 2024-11-21 N/A
admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account.