Skip to main content

Vendor archive

youlai CVEs

Beta · best-effort

14 CVEs tagged to vendor youlai1 Critical, 3 High, 0 Medium, 10 Low, 0 Unrated.

CVE-2026-3287

Published Feb 27, 2026

A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/c…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-15372

Published Dec 31, 2025

A weakness has been identified in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing of the file src/views/system/notice/index.vue of the compon…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15087

Published Dec 25, 2025

A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youla…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15086

Published Dec 25, 2025

A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15085

Published Dec 25, 2025

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15084

Published Dec 25, 2025

A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-oms/oms-boot/src/main/java/com/yo…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-66736

Published Dec 22, 2025

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identit…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66735

Published Dec 22, 2025

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root user…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14086

Published Dec 5, 2025

A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipulation of the argument openid r…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-14085

Published Dec 5, 2025

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId le…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-14052

Published Dec 5, 2025

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The m…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-14051

Published Dec 4, 2025

A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing ma…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-55471

Published Nov 26, 2025

Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55469

Published Nov 26, 2025

Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1