guchengwuyue
- Total products in the ecosystem
- 2
- Total vulnerabilities (90 days)
- 9
en
Verify to analyze this security profile
As of 09/20/2026, guchengwuyue recorded 9 security vulnerabilities in the last 90 days across 1 products, including 6 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, yshop-crm had the most security vulnerabilities in the guchengwuyue ecosystem, with 9 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-92463yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on System User Listing | Exploitation statusPublic exploit | FixYes | Affected productyshop-crm | Published09/16/2026 | SeverityHigh |
CVE-2026-92462yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlowStep | Exploitation statusPublic exploit | FixYes | Affected productyshop-crm | Published09/16/2026 | SeverityHigh |
CVE-2026-92461yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint | Exploitation statusPublic exploit | FixYes | Affected productyshop-crm | Published09/16/2026 | SeverityMedium |
CVE-2026-92460yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing | Exploitation statusPublic exploit | FixYes | Affected productyshop-crm | Published09/16/2026 | SeverityHigh |
CVE-2026-92459yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint | Exploitation statusPublic exploit | FixYes | Affected productyshop-crm | Published09/16/2026 | SeverityHigh |
CVE-2026-92458yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale | Exploitation statusPublic exploit | FixYes | Affected productyshop-crm | Published09/16/2026 | SeverityMedium |
CVE-2026-92457yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice | Exploitation statusPublic exploit | FixYes | Affected productyshop-crm | Published09/16/2026 | SeverityHigh |
CVE-2026-92456yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints | Exploitation statusPublic exploit | FixYes | Affected productyshop-crm | Published09/16/2026 | SeverityHigh |
CVE-2026-92455yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints | Exploitation statusPublic exploit | FixYes | Affected productyshop-crm | Published09/16/2026 | SeverityMedium |
CVE-2026-2146guchengwuyue yshopmall co.yixiang.utils.FileUtil updateAvatar unrestricted upload | Exploitation statusPublic exploit | FixNot confirmed | Affected productyshopmall | Published02/08/2026 | SeverityMedium |
CVE-2025-15496guchengwuyue yshopmall jobs getPage sql injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productyshopmall | Published01/09/2026 | SeverityMedium |
CVE-2025-25426 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published03/04/2025 | SeverityHigh |
CVE-2024-50648 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published11/15/2024 | SeverityCritical |