YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the ArticleAction.class.php file due to improper neutralization of user input in the article title field.
References
| Link | Resource |
|---|---|
| http://yccms.com | Broken Link |
| https://gist.github.com/b1uel0n3/8354650e683ffb0812bfe72b702b482d | Third Party Advisory |
Configurations
History
01 Dec 2025, 16:00
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:yccms:yccms:3.4:*:*:*:*:*:*:* | |
| First Time |
Yccms yccms
Yccms |
|
| References | () http://yccms.com - Broken Link | |
| References | () https://gist.github.com/b1uel0n3/8354650e683ffb0812bfe72b702b482d - Third Party Advisory |
24 Nov 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-24 20:15
Updated : 2025-12-01 16:00
NVD link : CVE-2025-64048
Mitre link : CVE-2025-64048
CVE.ORG link : CVE-2025-64048
JSON object : View
Products Affected
yccms
- yccms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
