CVE-2026-2934

A security vulnerability has been detected in YiFang CMS up to 2.0.5. This impacts the function update of the file app/db/admin/D_friendLinkGroup.php of the component Extended Management Module. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
References
Link Resource
https://github.com/ZZCTD/CVE/issues/5 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.347280 Permissions Required VDB Entry
https://vuldb.com/?id.347280 Third Party Advisory VDB Entry
https://vuldb.com/?submit.755296 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:yifangcms:yifang:*:*:*:*:*:*:*:*

History

24 Feb 2026, 17:23

Type Values Removed Values Added
References () https://github.com/ZZCTD/CVE/issues/5 - () https://github.com/ZZCTD/CVE/issues/5 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.347280 - () https://vuldb.com/?ctiid.347280 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347280 - () https://vuldb.com/?id.347280 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.755296 - () https://vuldb.com/?submit.755296 - Third Party Advisory, VDB Entry
First Time Yifangcms yifang
Yifangcms
CPE cpe:2.3:a:yifangcms:yifang:*:*:*:*:*:*:*:*

23 Feb 2026, 18:13

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de seguridad ha sido detectada en YiFang CMS hasta 2.0.5. Esto afecta la función update del archivo app/db/admin/D_friendLinkGroup.php del componente Módulo de Gestión Extendido. La manipulación del argumento Name conduce a cross site scripting. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado públicamente y puede ser utilizado.

22 Feb 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-22 09:16

Updated : 2026-02-24 17:23


NVD link : CVE-2026-2934

Mitre link : CVE-2026-2934

CVE.ORG link : CVE-2026-2934


JSON object : View

Products Affected

yifangcms

  • yifang
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')