CVE-2026-3742General(yifangcms / yifang)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of the argument Title results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • yifang

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-08); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
yifang

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-08: 2Mentions · 2026-08-09: 2Technical Details · 2026-03-08: 103-0808-09
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-082
Disclosure1General1
2026-08-092
General2
Full discourse4 posts
  • Diario฿itcoin@DiarioBitcoin
    General

    🚨Error 404: Noticia sobre el cryptominer Blanc no disponible🚨 El enlace de SecurityWeek que abordaba la vulnerabilidad CVE-2026-3742 ha fallado. Los lectores quedan sin acceso a información clave sobre la seguridad en Docker. La criptominería maliciosa representa una seria amenaza en servidores expuestos. Recomendamos revisar fuentes alternativas para estar informados sobre este tema crítico.

    Post summary

    The post notes that previous coverage of CVE-2026-3742 is unavailable and encourages readers to seek alternative sources for details.

    110001.3K
    213.3K followersView on X
  • Panorama Online@panorama_onl
    General

    Un enlace hacia un artículo de SecurityWeek sobre la vulnerabilidad CVE-2026-3742 en Docker ha dejado de funcionar, impidiendo el acceso a la información.

    Post summary

    The text notes a broken link to a SecurityWeek article on CVE‑2026‑3742 in Docker but gives no further technical or exploitation details.

    1000037
    734 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3742 A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of th… https://www.cve.org/CVERecord?id=CVE-2026-3742

    Post summary

    The text merely states a vulnerability exists in YiFang CMS 2.0.5 without providing any exploitation details, patch information, or in-depth technical description.

    0000097
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3742 - YiFang CMS D_singlePage.php update cross site scripting Intel Report: https://ift.tt/ByA8lW3

    Post summary

    The tweet announces a newly disclosed CVE (CVE-2026-3742) impacting YiFang CMS, highlighting an XSS flaw in the D_singlePage.php update functionality.

    0000028
    347 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyifangcmsyifang2.0.5--

Explore more