vciy

CVEs we hold for Yonyou

Records whose assigning authority named Yonyou as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-1179Yonyou KSOA HTTP GET Parameter user_popedom.jsp sql injectionYonyou KSOA
CVE-2026-1178Yonyou KSOA HTTP GET Parameter select.jsp sql injectionYonyou KSOA
CVE-2026-1177Yonyou KSOA HTTP GET Parameter save_folder.jsp sql injectionYonyou KSOA
CVE-2026-1133Yonyou KSOA HTTP GET Parameter folder.jsp sql injectionYonyou KSOA
CVE-2026-1132Yonyou KSOA HTTP GET Parameter edit_folder.jsp sql injectionYonyou KSOA
CVE-2026-1131Yonyou KSOA HTTP GET Parameter save_catalog.jsp sql injectionYonyou KSOA
CVE-2026-1130Yonyou KSOA HTTP GET Parameter worksadd_plan.jsp sql injectionYonyou KSOA
CVE-2026-1129Yonyou KSOA HTTP GET Parameter worksadd.jsp sql injectionYonyou KSOA
CVE-2026-1124Yonyou KSOA HTTP GET Parameter work_report.jsp sql injectionYonyou KSOA
CVE-2026-1123Yonyou KSOA HTTP GET Parameter work_mod.jsp sql injectionYonyou KSOA
CVE-2026-1122Yonyou KSOA HTTP GET Parameter work_info.jsp sql injectionYonyou KSOA
CVE-2026-1121Yonyou KSOA HTTP GET Parameter del_workplan.jsp sql injectionYonyou KSOA
CVE-2026-1120Yonyou KSOA HTTP GET Parameter del_work.jsp sql injectionYonyou KSOA
CVE-2025-3562Yonyou YonBIP userfile FileInputStream path traversalYonyou YonBIP
CVE-2025-34039Yonyou NC BeanShell Command InjectionYonyou Co., Ltd. UFIDA NC
CVE-2025-2712Yonyou UFIDA ERP-NC top.jsp cross site scriptingYonyou UFIDA ERP-NC
CVE-2025-2711Yonyou UFIDA ERP-NC systop.jsp cross site scriptingYonyou UFIDA ERP-NC
CVE-2025-2710Yonyou UFIDA ERP-NC menu.jsp cross site scriptingYonyou UFIDA ERP-NC
CVE-2025-2709Yonyou UFIDA ERP-NC login.jsp cross site scriptingYonyou UFIDA ERP-NC
CVE-2025-15436Yonyou KSOA work_edit.jsp sql injectionYonyou KSOA
CVE-2025-15435Yonyou KSOA work_update.jsp sql injectionYonyou KSOA
CVE-2025-15434Yonyou KSOA PrintZPYG.jsp sql injectionYonyou KSOA
CVE-2025-15425Yonyou KSOA HTTP GET Parameter del_user.jsp sql injectionYonyou KSOA
CVE-2025-15424Yonyou KSOA HTTP GET Parameter agent_worksdel.jsp sql injectionYonyou KSOA
CVE-2025-15421Yonyou KSOA HTTP GET Parameter agent_worksadd.jsp sql injectionYonyou KSOA
CVE-2025-15420Yonyou KSOA agent_work_report.jsp sql injectionYonyou KSOA
CVE-2025-14185Yonyou U8 Cloud AppServletService.class sql injectionYonyou U8 Cloud
CVE-2025-12344Yonyou U8 Cloud Request Header NCloudGatewayServlet unrestricted uploadYonyou U8 Cloud
CVE-2024-58385Yonyou U8 CRM SQL Injection via fillbacksettingedit.phpYonyou U8 CRM
CVE-2023-54398Yonyou U8 Cloud Java Deserialization RCE via FileManageServletYonyou U8 Cloud
CVE-2022-50973Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload ServletYonyou Network Technology Co., Ltd. KSOA

31 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.