Writeup Exploits

60,635 exploits tracked across all sources.

Sort: Activity Stars
CVE-2026-2146 WRITEUP MEDIUM
guchengwuyue yshopmall <1.9.1 - Unrestricted Upload
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 6.3
CVE-2026-2146 WRITEUP MEDIUM
guchengwuyue yshopmall <1.9.1 - Unrestricted Upload
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 6.3
CVE-2025-25426 WRITEUP HIGH
yshopmall <= 1.9.0 - SQL Injection in Image Listing Interface
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
CVSS 7.2
CVE-2025-15496 WRITEUP MEDIUM
yshopmall < 1.9.1 - SQL Injection via /api/jobs sort Parameter
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 6.3
CVE-2025-15496 WRITEUP MEDIUM
yshopmall < 1.9.1 - SQL Injection via /api/jobs sort Parameter
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 6.3
CVE-2025-15496 WRITEUP MEDIUM
yshopmall < 1.9.1 - SQL Injection via /api/jobs sort Parameter
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 6.3
CVE-2025-15437 WRITEUP LOW
LigeroSmart < 6.1.24 - Cross-Site Scripting via REQUEST_URI Manipulation
A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 6.1.26 and 6.3 is able to mitigate this issue. The patch is named 264ac5b2be5b3c673ebd8cb862e673f5d300d9a7. The affected component should be upgraded.
CVSS 3.5
CVE-2026-2547 WRITEUP LOW
ligerosmart < 6.1.26 - Cross-Site Scripting via Subaction Parameter in AgentDashboard
A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing a manipulation of the argument Subaction results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-2547 WRITEUP LOW
ligerosmart < 6.1.26 - Cross-Site Scripting via Subaction Parameter in AgentDashboard
A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing a manipulation of the argument Subaction results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-2546 WRITEUP LOW
LigeroSmart < 6.1.26 - Cross-Site Scripting via SortBy Argument in /otrs/index.pl
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument SortBy leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-2546 WRITEUP LOW
LigeroSmart < 6.1.26 - Cross-Site Scripting via SortBy Argument in /otrs/index.pl
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument SortBy leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-2545 WRITEUP LOW
LigeroSmart < 6.1.26 - Cross-Site Scripting via AgentTicketSearch Profile Parameter
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-2545 WRITEUP LOW
LigeroSmart < 6.1.26 - Cross-Site Scripting via AgentTicketSearch Profile Parameter
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-1049 WRITEUP LOW
LigeroSmart < 6.1.26 - Cross-Site Scripting via TicketID Parameter in /otrs/index.pl
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument TicketID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-1049 WRITEUP LOW
LigeroSmart < 6.1.26 - Cross-Site Scripting via TicketID Parameter in /otrs/index.pl
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument TicketID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-1048 WRITEUP LOW
ligerosmart < 6.1.26 - Cross-Site Scripting via TicketID Parameter in AgentTicketZoom
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketZoom. This manipulation of the argument TicketID causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-1048 WRITEUP LOW
ligerosmart < 6.1.26 - Cross-Site Scripting via TicketID Parameter in AgentTicketZoom
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketZoom. This manipulation of the argument TicketID causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2025-15437 WRITEUP LOW
LigeroSmart < 6.1.24 - Cross-Site Scripting via REQUEST_URI Manipulation
A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 6.1.26 and 6.3 is able to mitigate this issue. The patch is named 264ac5b2be5b3c673ebd8cb862e673f5d300d9a7. The affected component should be upgraded.
CVSS 3.5
CVE-2025-15437 WRITEUP LOW
LigeroSmart < 6.1.24 - Cross-Site Scripting via REQUEST_URI Manipulation
A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 6.1.26 and 6.3 is able to mitigate this issue. The patch is named 264ac5b2be5b3c673ebd8cb862e673f5d300d9a7. The affected component should be upgraded.
CVSS 3.5
CVE-2026-1049 WRITEUP LOW
LigeroSmart < 6.1.26 - Cross-Site Scripting via TicketID Parameter in /otrs/index.pl
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument TicketID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2026-1048 WRITEUP LOW
ligerosmart < 6.1.26 - Cross-Site Scripting via TicketID Parameter in AgentTicketZoom
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketZoom. This manipulation of the argument TicketID causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.5
CVE-2025-15437 WRITEUP LOW
LigeroSmart < 6.1.24 - Cross-Site Scripting via REQUEST_URI Manipulation
A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 6.1.26 and 6.3 is able to mitigate this issue. The patch is named 264ac5b2be5b3c673ebd8cb862e673f5d300d9a7. The affected component should be upgraded.
CVSS 3.5
CVE-2026-1050 WRITEUP HIGH
risenet-y9boot-support-platform-service - SQL Injection in REST Authenticate Endpoint
A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 7.3
CVE-2026-1050 WRITEUP HIGH
risenet-y9boot-support-platform-service - SQL Injection in REST Authenticate Endpoint
A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 7.3
CVE-2026-1050 WRITEUP HIGH
risenet-y9boot-support-platform-service - SQL Injection in REST Authenticate Endpoint
A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 7.3