CVE-2020-35971: Yzmcms

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.

Affected products

  • Yzmcms Yzmcms: version 5.8 only

Published 2021-06-03. Last modified 2026-06-17.