Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/yshop-crm

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-92463 is an authorization failure vulnerability in yshop-crm through version 2.1.3. The GET /admin-api/system/user/page endpoint lacks proper authorization checks because the @PreAuthorize annotation is commented out. This allows authenticated back-office users without the required system:user:list permission but with a role having data scope ALL to enumerate all users and access sensitive user information such as login names, nicknames, departments, email addresses, mobile numbers, and last login details.

Join the discussion

CVE-2026-92462 is a high-severity vulnerability in yshop-crm up to version 2.1.3 where authorization checks are missing on the deleteFlowStep endpoint. This flaw allows any authenticated back-office user to delete approval workflow steps without proper permissions. These approval steps control critical processes such as contract, receivable, and invoice finalization, potentially disrupting business operations.

Join the discussion

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain topology, step ordering, approver identifiers, and personal information including login names, nicknames, departments, email addresses, mobile numbers and last login IP addresses.

Join the discussion

yshop-crm versions up to 2.1.3 have a missing authorization vulnerability on the GET /admin-api/crm/operatelog/page endpoint. This flaw allows any authenticated back-office user to access the full installation-wide audit trail without proper permission checks. Sensitive information exposed includes operator names, display nicknames, client IP addresses, User-Agent strings, request URLs, action details, and customer identifiers.

Join the discussion

yshop-crm versions up to 2.1.3 have a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint. Authenticated back-office users can claim sales leads without proper permission checks, allowing them to reassign leads from other employees to themselves. There is no access logging or quota validation to prevent bulk lead theft.

Join the discussion

yshop-crm versions up to 2.1.3 have a missing authorization vulnerability in the StoreProductController onSale handler. Authenticated back-office users can exploit this flaw to change the sale status of products without proper permission checks by accessing the GET /admin-api/product/store-product/sale endpoint. This allows unauthorized modification of product availability, including withdrawing or re-enabling products for sale.

Join the discussion

yshop-crm versions up to 2.1.3 have a missing authorization vulnerability in the CrmInvoiceController's issueInvoice endpoint. Authenticated back-office users can exploit this flaw to issue arbitrary invoices without proper permissions. This allows modification of invoice status, inflation of contract invoiced amounts with attacker-chosen values, and sending invoice emails to arbitrary addresses.

Join the discussion

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared Redis keys controlling customer auto-recycling behavior, causing mass customer data deletion, disabling lead recycling, or blocking customer creation across the deployment.

Join the discussion

CVE-2026-92455 is a medium severity vulnerability in guchengwuyue yshop-crm versions up to 2.1.3. It involves missing authorization checks on the sendSms and sendMail endpoints in the CrmCustomerController, allowing any authenticated back-office user to send SMS and email messages to arbitrary customers without proper permission.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/yshop-crm
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses