yzcheng90 has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 8.2 (high), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.2
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Weakness classes
Products
- X-SpringBoot 4
Worst active — by depth score
CVE-2026-97063Critical· 9.1X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners62CVE-2026-97064Critical· 9.1X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed50CVE-2026-97060High· 7.2X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification40CVE-2026-100192Medium· 6.5X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering36
yzcheng90 vulnerabilities
CVEs affecting yzcheng90, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-97064Critical· 9.1X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emai…
CVE-2026-97060High· 7.2X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords …
CVE-2026-100192Medium· 6.5X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering
X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send ar…
CVE-2026-97063Critical· 9.1PoCX-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners
X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobil…