Back to overview

CVE-2026-13529

MEDIUM
5.6
CVSS 3.1
Description
A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl can lead to sql injection. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is reported as difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Metadata

CVE ID
CVE-2026-13529
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-28 07:59 UTC
Published
2026-06-29 03:00 UTC
Last updated
2026-06-29 03:00 UTC
Primary CWE
CWE-89
SQL Injection
Vendor / Product
n/a / YzmCMS
Sources
cve.org  ·  NVD

Severity & Metrics

5.6 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Affected products (1)
VendorProductPlatformVersions
n/a YzmCMS 7.0, 7.1, 7.2, 7.3 …
Weakness (CWE)
CWESourceDescription
CWE-74 cna Injection
CWE-89 cna SQL Injection
CVSS scores (4)
ScoreSeverityVersionSourceVector
6.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
5.6 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
5.6 MEDIUM 3.0 cna CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
5.1 N/D 2.0 cna AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
References (5)
Back to overview