CVE-2022-45276: Eyunjing Yjcms

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.

Affected products

Published 2022-11-23. Last modified 2026-06-17.