CVE-2018-10704: YII2CMF Project YII2CMF
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
yidashi yii2cmf 2.0 has XSS via the /search q parameter.
Affected products
- YII2CMF Project YII2CMF: version 2.0 only
Published 2020-03-12. Last modified 2026-06-17.