CVE-2018-13025: Yxcms

Medium severity, CVSS 4.9. EPSS: 0.8% chance of exploitation in the next 30 days.

protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via the index.php?r=admin/photo/delpic picname parameter.

Affected products

  • Yxcms Yxcms: version 1.4.7 only

Published 2018-06-29. Last modified 2026-06-17.