
BREAKING: CVE-2026-6633 XSS bug in Yifang CMS up to 2.0.5 now has public exploit code, vendor silent and no patch available. https://threatcluster.io/cluster/cve-2026-6633-xss-vulnerability-in-yifang-cms-exposes-users--9beb3395
Post summary
CVE-2026-6633 is an XSS flaw in Yifang CMS (up to 2.0.5) with an openly available exploit; the vendor has not released a patch.


