Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Yifan — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting Yifan. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Yifan is a web application framework primarily used for building content management systems and e-commerce platforms. Historically, it has been susceptible to multiple vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, with 13 CVEs documented. The framework's modular architecture introduces potential risks through third-party extensions. Notable security characteristics include its extensive use of dynamic rendering and client-side processing, which have contributed to XSS vulnerabilities. While no major public security incidents have been widely reported, the consistent discovery of flaws in input validation and access control mechanisms suggests ongoing security challenges for developers implementing Yifan-based solutions.

Top products by Yifan: YF325

This page lists every published CVE security advisory associated with Yifan. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.