yonyou has 5 CVEs on record between 2022 and 2026. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.3 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-89 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2024-58385Critical· 9.8Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL querie…66CVE-2023-54398Critical· 9.8Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…66CVE-2022-26263Medium· 6.1Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.54CVE-2026-94492Medium· 6.3A security vulnerability has been detected in Yonyou U8cloud 5.x47CVE-2026-94491High· 7.3A weakness has been identified in Yonyou KSOA 9.040
yonyou vulnerabilities
CVEs affecting yonyou, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-94492Medium· 6.3PoCA security vulnerability has been detected in Yonyou U8cloud 5.x
A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation of the argument operator leads to sq…
CVE-2026-94491High· 7.3A weakness has been identified in Yonyou KSOA 9.0
A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remote…
CVE-2024-58385Critical· 9.8PoCYonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL querie…
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL querie…
CVE-2023-54398Critical· 9.8PoCYonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…
Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…
CVE-2022-26263Medium· 6.1PoCYonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.
Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.