CVE-2025-56304: Yzmcms

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.

Affected products

  • Yzmcms Yzmcms: up to and including 7.3

Published 2025-09-23. Last modified 2026-07-05.