Skip to main content

Vendor archive

guchengwuyue CVEs

Beta · best-effort

4 CVEs tagged to vendor guchengwuyue1 Critical, 1 High, 0 Medium, 2 Low, 0 Unrated.

CVE-2026-2146

Published Feb 8, 2026

A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.u…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-15496

Published Jan 9, 2026

A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql inj…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-50648

Published Nov 15, 2024

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1