CVE-2026-6633Disclosure

LOWCVSS 2.0 · LOW

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_admin.php of the component Extended Management Module. The manipulation of the argument Account results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-20: 3PoC Mentioned / Linked · 2026-04-20: 1Exploit Tool / Code · 2026-04-20: 1Technical Details · 2026-04-20: 204-20
Signal classification3 categories
Disclosure
133.3%
Exploit
133.3%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • ThreatCluster@threatcluster
    Exploit

    BREAKING: CVE-2026-6633 XSS bug in Yifang CMS up to 2.0.5 now has public exploit code, vendor silent and no patch available. https://threatcluster.io/cluster/cve-2026-6633-xss-vulnerability-in-yifang-cms-exposes-users--9beb3395

    Post summary

    CVE-2026-6633 is an XSS flaw in Yifang CMS (up to 2.0.5) with an openly available exploit; the vendor has not released a patch.

    0000049
    160 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6633 Cross Site Scripting in Yifang CMS Up To 2.0.5 Extended Management Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6633

    Post summary

    The text merely announces CVE-2026-6633 with a brief description and a link, providing no additional detail.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6633 A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_… https://www.cve.org/CVERecord?id=CVE-2026-6633

    Post summary

    A new vulnerability (CVE-2026-6633) has been discovered in Yifang CMS up to version 2.0.5, affecting the function store within a specific plugin file, but no proof of concept, exploit, or patch information is provided.

    0000051
    57.2K followersView on X

Explore more