📦 Yshopmall

by Guchengwuyue

🔍 What is Yshopmall?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-50648

CRITICAL CVSS 9.8 Nov 15, 2024

yshopmall V1.0 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files, potentially leading to remote code execution (RCE) and server takeover if the server is ...

CVE-2025-25426

HIGH CVSS 7.2 Mar 4, 2025

CVE-2025-25426 is an SQL injection vulnerability in yshopmall's image listing interface that allows attackers to execute arbitrary SQL commands. This affects all yshopmall installations running versio...

CVE-2026-2146

MEDIUM CVSS 6.3 Feb 8, 2026

This vulnerability allows remote attackers to upload arbitrary files without restrictions through the updateAvatar function in guchengwuyue yshopmall. Attackers can exploit this to upload malicious fi...

CVE-2025-15496

MEDIUM CVSS 6.3 Jan 9, 2026

This SQL injection vulnerability in guchengwuyue yshopmall allows attackers to manipulate database queries through the 'sort' parameter in the /api/jobs endpoint. Attackers can potentially read, modif...