CVE-2018-7479: Yzmcms
Medium severity, CVSS 5.3. EPSS: 2% chance of exploitation in the next 30 days.
YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.
Affected products
- Yzmcms Yzmcms: version 3.6 only
Published 2018-02-26. Last modified 2026-06-17.