VYPR
Vendor

yshopmall

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2024-50648CriNov 15, 2024
    risk 0.64cvss 9.8epss 0.01

    yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

  • CVE-2025-25426HigMar 4, 2025
    risk 0.47cvss 7.2epss 0.00

    yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.

  • CVE-2026-75308MedSep 9, 2026
    risk 0.40cvss 6.1epss 0.00

    yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.