CVE-2024-35110: Yzmcms

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.

Affected products

  • Yzmcms Yzmcms: version 7.1 only

Published 2024-05-17. Last modified 2026-06-17.