« Volver al listado

Guchengwuyue

Guchengwuyue Yshopmall: vulnerabilidades y CVE

Guchengwuyue Yshopmall tiene 5 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses3
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-75308Media (6.1)0.25%—9 sept 2026
yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other…
CVE-2026-2146Baja (2.1)0.34%—8 feb 2026
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation…
CVE-2025-15496Baja (2.1)0.39%—9 ene 2026
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated…
CVE-2025-25426Alta (7.2)0.44%—4 mar 2025
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
CVE-2024-50648Crítica (9.8)1.0%—15 nov 2024
yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System1
  2. T1059 Command and Scripting Interpreter1
  3. T1190 Exploit Public-Facing Application1
  4. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.