CVE-2018-10026: Yzmcms
Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
Affected products
- Yzmcms Yzmcms: version 3.7.1 only
Published 2018-04-11. Last modified 2026-06-17.