VYPR
Vendor

Guchengwuyue

Products
2
CVEs
7
Across products
7
Status
Private

Products

2

Recent CVEs

7
  • CVE-2024-50648CriNov 15, 2024
    risk 0.64cvss 9.8epss 0.01

    yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

  • CVE-2025-25426HigMar 4, 2025
    risk 0.47cvss 7.2epss 0.00

    yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.

  • CVE-2026-92456HigSep 16, 2026
    risk 0.46cvss 7.1epss 0.01

    yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can…

  • CVE-2026-92460MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.00

    yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display…

  • CVE-2026-92459MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.00

    yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign…

  • CVE-2026-2146MedFeb 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The…

  • CVE-2025-15496MedJan 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be…