VulnSea

yzcheng90 has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 8.2 (high), with 2 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.2
Publish → KEV
—
Last 90 days
4 prev 0

Products

  • X-SpringBoot 4
4
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

yzcheng90 vulnerabilities

CVEs affecting yzcheng90, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-97064Critical· 9.1
yesterday

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emai…

▾ Midnightyzcheng90 · X-SpringBootvia NVD
CVE-2026-97060High· 7.2
yesterday

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords …

▾ Twilightyzcheng90 · X-SpringBootvia NVD
CVE-2026-100192Medium· 6.5
yesterday

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send ar…

▾ Sunlityzcheng90 · X-SpringBootvia NVD
CVE-2026-97063Critical· 9.1PoC
yesterday

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobil…

▾ Abyssalyzcheng90 · X-SpringBootvia NVD
yzcheng90 vulnerabilities (CVEs) · VulnSea