CVE-2026-2933 | YiFang CMS up to 2.0.5 Extended Management D_adManage.php update Name cross site scripting
A vulnerability categorized as problematic has been discovered in YiFang CMS up to 2.0.5. This affects the function update of the file app/db/admin/D_adManage.php of the component Extended Management Module. Executing a manipulation of the argument Name can lead to cross site scripting.
This vulnerability appears as CVE-2026-2933. The attack may be performed from remote. In addition, an exploit is available.