Yonyou
Yonyou Ksoa: vulnerabilidades y CVE
Yonyou Ksoa tiene 22 vulnerabilidades publicadas, 22 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses22
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94491 | Media (5.5) | 0.41% | — | 21 sept 2026 | A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch… |
| CVE-2022-50973 | Crítica (9.3) | 1.5% | — | 2 jul 2026 | Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request… |
| CVE-2026-1179 | Media (5.5) | 0.41% | — | 19 ene 2026 | A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument folderid results in sql… |
| CVE-2026-1178 | Media (5.5) | 0.41% | — | 19 ene 2026 | A security vulnerability has been detected in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /kmf/select.jsp of the component HTTP GET Parameter Handler. The manipulation of the… |
| CVE-2026-1177 | Media (5.5) | 0.41% | — | 19 ene 2026 | A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /kmf/save_folder.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the… |
| CVE-2026-1133 | Media (5.5) | 0.54% | — | 19 ene 2026 | A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /kmf/folder.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument folderid… |
| CVE-2026-1132 | Media (5.5) | 0.56% | — | 19 ene 2026 | A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /kmf/edit_folder.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument folderid… |
| CVE-2026-1131 | Media (5.5) | 0.56% | — | 19 ene 2026 | A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument catalogid leads to sql… |
| CVE-2026-1130 | Media (5.5) | 0.54% | — | 19 ene 2026 | A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_plan.jsp of the component HTTP GET Parameter Handler. This manipulation of the argument ID causes sql… |
| CVE-2026-1129 | Media (5.5) | 0.54% | — | 19 ene 2026 | A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in… |
| CVE-2026-1124 | Media (5.5) | 0.46% | — | 18 ene 2026 | A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report.jsp of the component HTTP GET Parameter Handler. Performing a… |
| CVE-2026-1123 | Media (5.5) | 0.46% | — | 18 ene 2026 | A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument ID leads to sql… |
| CVE-2026-1122 | Media (5.5) | 0.46% | — | 18 ene 2026 | A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp of the component HTTP GET Parameter Handler. This manipulation of the argument ID causes sql… |
| CVE-2026-1121 | Media (5.5) | 0.50% | — | 18 ene 2026 | A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql… |
| CVE-2026-1120 | Media (5.5) | 0.49% | — | 18 ene 2026 | A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID leads… |
| CVE-2025-15436 | Media (5.5) | 0.45% | — | 2 ene 2026 | A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack… |
| CVE-2025-15435 | Media (5.5) | 0.41% | — | 2 ene 2026 | A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can… |
| CVE-2025-15434 | Media (5.5) | 0.40% | — | 2 ene 2026 | A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The manipulation of the argument zpjhid results in sql injection. It is possible to launch the attack… |
| CVE-2025-15425 | Media (5.5) | 0.52% | — | 2 ene 2026 | A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_user.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument ID… |
| CVE-2025-15424 | Media (5.5) | 0.46% | — | 2 ene 2026 | A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_worksdel.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument… |
| CVE-2025-15421 | Media (5.5) | 0.46% | — | 2 ene 2026 | A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results… |
| CVE-2025-15420 | Media (5.5) | 0.46% | — | 2 ene 2026 | A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads to sql injection. The attack can be… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.