CVE-2020-20287: Yccms

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.

Affected products

  • Yccms Yccms: version 3.3 only

Published 2021-02-01. Last modified 2026-06-17.