Guchengwuyue
Guchengwuyue Yshopmall: vulnerabilidades y CVE
Guchengwuyue Yshopmall tiene 5 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-75308 | Media (6.1) | 0.25% | — | 9 sept 2026 | yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other… |
| CVE-2026-2146 | Baja (2.1) | 0.34% | — | 8 feb 2026 | A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation… |
| CVE-2025-15496 | Baja (2.1) | 0.39% | — | 9 ene 2026 | A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated… |
| CVE-2025-25426 | Alta (7.2) | 0.44% | — | 4 mar 2025 | yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface. |
| CVE-2024-50648 | Crítica (9.8) | 1.0% | — | 15 nov 2024 | yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.