CVE-2026-6633: XSS Vulnerability in Yifang CMS Exposes Users to Remote Attacks
Article Content
- •CVE-2026-6633 affects Yifang CMS versions up to 2.0.5, allowing remote XSS attacks.
- •Public exploit code is available, increasing the risk of exploitation despite no confirmed attacks.
- •The vendor has not responded to disclosure attempts and no patch is currently available.
A cross-site scripting (XSS) vulnerability, identified as CVE-2026-6633, has been discovered in Yifang CMS versions up to 2.0.5. The flaw resides in the store function of the file plugins/yifang_backend_account/logic/admin/L_rbac_admin.php within the Extended Management Module. Attackers can exploit this vulnerability by manipulating the Account argument, allowing them to execute malicious scripts remotely. The vulnerability has a medium severity rating with a CVSS score of 5.1. Public exploit code is now available, increasing the risk of attacks, although no active exploitation has been confirmed in the wild. The vendor has not responded to disclosure attempts, and no official patch or remediation is currently available. Users are advised to implement web application firewall (WAF) rules and monitor for suspicious activity. Regular checks for updates from the vendor are recommended.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-6633 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple WordPress Plugins Face Vulnerabilities Requiring Immediate Updates Three WordPress plugins have been reported with vulnerabilities: the GiveWP plugin (version 4.16.9) has a Cross Site Scripting (XSS) vulnerability, while both the Siteskite (version 2.1.8) and Cartflows (version 3.2.0) plugins have Remote Code Execution (RCE) vulnerabilities. The XSS vulnerability allows attackers to…