๐Ÿ” CVE Alert

CVE-2026-105156

LOW 3.7

YzmCMS MD5 system.func.php password weak password hash

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computational effort. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The vendor kindly explains: "Our regular release cycle is about 6 months. The last release was in the previous month, and our next scheduled version will be released in March 2027. We will implement the backward-compatible gradual hash migration feature in this upcoming release. (...) Before the new version is available, we will publish security mitigation guidance on our official documentation for existing deployers to reduce the risk."

CWE CWE-916 CWE-326
Vendor n/a
Product yzmcms
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for n/a yzmcms

Be the first to know when new low vulnerabilities affecting n/a yzmcms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / YzmCMS
7.0 7.1 7.2 7.3 7.4 7.5 7.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/413375 vuldb.com: https://vuldb.com/vuln/413375/cti vuldb.com: https://vuldb.com/cve/CVE-2026-105156 vuldb.com: https://vuldb.com/submit/953155 github.com: https://github.com/Witiers/CVEs/issues/6

Credits

๐Ÿ” Witiers (VulDB User) VulDB CNA Team