guchengwuyue yshop-crm
9 known vulnerabilities in guchengwuyue yshop-crm, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-92463 CVSS 7.1 high yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize…
- CVE-2026-92462 CVSS 7.1 high yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated…
- CVE-2026-92461 CVSS 5.3 medium yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any…
- CVE-2026-92460 CVSS 7.1 high yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated…
- CVE-2026-92459 CVSS 7.1 high yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows…
- CVE-2026-92458 CVSS 5.3 medium yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows…
- CVE-2026-92457 CVSS 7.1 high yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows…
- CVE-2026-92456 CVSS 7.1 high yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing…
- CVE-2026-92455 CVSS 5.3 medium yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any…