CVE-2015-1576: Yuba u5cms
High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.php, (5) new2.php, or (6) rename2.php in u5admin/; (7) c parameter to u5admin/editor.php; (8) typ parameter to u5admin/meta2.php; or (9) newname parameter to u5admin/rename2.php.
Affected products
- Yuba u5cms: up to and including 3.9.3
Published 2015-02-11. Last modified 2026-06-17.