YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.Referenceshttps://github.com/yzmcms/yzmcms/issues/60