VYPR

U8cloud

by Yonyou

CVEs (4)

  • CVE-2023-54398CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can…

  • CVE-2026-94492MedSep 22, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation of the argument operator leads to sql injection. The attack can be initiated…

  • CVE-2025-14185MedDec 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Yonyou U8 Cloud 5.0/5.0sp/5.1/5.1sp. The affected element is an unknown function of the file nc/pubitf/erm/mobile/appservice/AppServletService.class. Such manipulation of the argument usercode leads to sql injection. The attack may be launched…

  • CVE-2025-12344MedOct 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /service/NCloudGatewayServlet of the component Request Header Handler. Such manipulation of the argument ts/sign leads to unrestricted upload. The attack may be…