Yshopmall
by Guchengwuyue
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-50648 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2024 | yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files. | ||
| CVE-2025-25426 | Hig | 0.47 | 7.2 | 0.00 | Mar 4, 2025 | yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface. | ||
| CVE-2026-2146 | Med | 0.41 | 6.3 | 0.00 | Feb 8, 2026 | A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The… | ||
| CVE-2025-15496 | Med | 0.41 | 6.3 | 0.00 | Jan 9, 2026 | A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be… |
- risk 0.64cvss 9.8epss 0.01
yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
- risk 0.47cvss 7.2epss 0.00
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
- risk 0.41cvss 6.3epss 0.00
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be…