yzcheng90 X-SpringBoot

4 known vulnerabilities in yzcheng90 X-SpringBoot, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-97064 CVSS 9.3 critical X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed…
  • CVE-2026-97063 CVSS 9.3 critical X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET…
  • CVE-2026-97060 CVSS 8.6 high X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete…
  • CVE-2026-100192 CVSS 6.9 medium X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication…