PatchSiren

YzmCMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH YzmCMS CVE published 2026-08-28

CVE-2026-75417

The CVE-2026-75417 vulnerability is a SQL injection issue in YzmCMS 7.5, occurring in the get_arrchildid() function within application/admin/controller/category.class.php. The user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization, allowing authenticated administrators to execute arbitrary SQL queries via boolean-based blind injection, poten [truncated]