Guchengwuyue
Products
2- 4 CVEs
- 3 CVEs
Recent CVEs
7| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-50648 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2024 | yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files. | ||
| CVE-2025-25426 | Hig | 0.47 | 7.2 | 0.00 | Mar 4, 2025 | yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface. | ||
| CVE-2026-92456 | Hig | 0.46 | 7.1 | 0.01 | Sep 16, 2026 | yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can… | ||
| CVE-2026-92460 | Med | 0.42 | 6.5 | 0.00 | Sep 16, 2026 | yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display… | ||
| CVE-2026-92459 | Med | 0.42 | 6.5 | 0.00 | Sep 16, 2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign… | ||
| CVE-2026-2146 | Med | 0.41 | 6.3 | 0.00 | Feb 8, 2026 | A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The… | ||
| CVE-2025-15496 | Med | 0.41 | 6.3 | 0.00 | Jan 9, 2026 | A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be… |
- risk 0.64cvss 9.8epss 0.01
yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
- risk 0.47cvss 7.2epss 0.00
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
- risk 0.46cvss 7.1epss 0.01
yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can…
- risk 0.42cvss 6.5epss 0.00
yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display…
- risk 0.42cvss 6.5epss 0.00
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign…
- risk 0.41cvss 6.3epss 0.00
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be…