Code Audit: YXCMS 1.4.6 Vulnerability Collection
A retrospective audit of YXCMS 1.4.6 covering five vulnerability classes: stored XSS in the guestbook via array-based regex bypass, chained with CSRF to drop a PHP webshell, plus arbitrary file deletion, backend file write, and numeric SQL injection.