A security vulnerability has been detected in YiFang CMS up to 2.0.5. This impacts the function update of the file app/db/admin/D_friendLinkGroup.php of the component Extended Management Module. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yifangcms
Yifangcms yifang |
|
| CPEs | cpe:2.3:a:yifangcms:yifang:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yifangcms
Yifangcms yifang |
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yifang
Yifang cms |
|
| Vendors & Products |
Yifang
Yifang cms |
Sun, 22 Feb 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in YiFang CMS up to 2.0.5. This impacts the function update of the file app/db/admin/D_friendLinkGroup.php of the component Extended Management Module. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Title | YiFang CMS Extended Management D_friendLinkGroup.php update cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-02-22T08:02:08.708Z
Updated: 2026-02-25T18:33:35.658Z
Reserved: 2026-02-21T08:08:49.837Z
Link: CVE-2026-2934
No data.
Status : Analyzed
Published: 2026-02-22T09:16:11.173
Modified: 2026-02-24T17:23:16.303
Link: CVE-2026-2934
No data.