VulnSea

guchengwuyue has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 9. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-862 (9).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
9 prev 0

Weakness classes

Products

  • yshop-crm 9
9
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

guchengwuyue vulnerabilities

CVEs affecting guchengwuyue, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-92455Medium· 4.3PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /a…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.36%via NVD
CVE-2026-92458Medium· 4.3PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can invoke the GET /admin-api/produc…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.35%via NVD
CVE-2026-92457Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/i…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-92456High· 7.1PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer …

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer …

▾ Midnightguchengwuyue · yshop-crmEPSS 0.50%via NVD
CVE-2026-92463Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission t…

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission t…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.46%via NVD
CVE-2026-92460Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to …

▾ Twilightguchengwuyue · yshop-crmEPSS 0.45%via NVD
CVE-2026-92461Medium· 4.3PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain …

▾ Twilightguchengwuyue · yshop-crmEPSS 0.38%via NVD
CVE-2026-92459Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can in…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-92462Medium· 6.5PoC
1w ago

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers can invoke the DELETE /adm…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
guchengwuyue vulnerabilities (CVEs) · VulnSea