VYPR

yoshop2.0

by Xany

CVEs (1)

  • CVE-2025-56161HigOct 2, 2025
    risk 0.49cvss 7.5epss 0.01

    YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field filtering; because User.php defines no $hidden or $visible attributes, sensitive fields (bcrypt…