CVE-2026-2934 | YiFang CMS up to 2.0.5 Extended Management D_friendLinkGroup.php update Name cross site scripting
A vulnerability identified as problematic has been detected in YiFang CMS up to 2.0.5. This impacts the function update of the file app/db/admin/D_friendLinkGroup.php of the component Extended Management Module. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is traded as CVE-2026-2934. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.