VendorsGuchengwuyueyshopmallall versions
Vulnerabilities

Guchengwuyue Yshopmall

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2024-50648
yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
Published 2024-11-15 · Analyzed
9.8EPSS 0.010
CVE-2025-15496
guchengwuyue yshopmall jobs getPage sql injection
Published 2026-01-09 · Modified
9.8EPSS 0.004
CVE-2026-2146
guchengwuyue yshopmall co.yixiang.utils.FileUtil updateAvatar unrestricted upload
Published 2026-02-08 · Analyzed
8.8EPSS 0.003
CVE-2025-25426
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
Published 2025-03-04 · Analyzed
7.2EPSS 0.004