CVE-2026-2932
YiFang CMS Extended Management D_adPosition.php update cross site scripting
CVSS Score
2.4
EPSS Score
0.0%
EPSS Percentile
0th
A security flaw has been discovered in YiFang CMS up to 2.0.5. The impacted element is the function update of the file app/db/admin/D_adPosition.php of the component Extended Management Module. Performing a manipulation of the argument name/index results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
| CWE | CWE-79 CWE-94 |
| Vendor | yifang |
| Product | cms |
| Published | Feb 22, 2026 |
| Last Updated | Feb 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for yifang cms
Be the first to know when new low vulnerabilities affecting yifang cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
YiFang / CMS
2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5
References
Credits
๐ ZZCTD (VulDB User)