Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-70059 +1 in the same advisory: …70060 | An issue pertaining to CWE-400: An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denial of service. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2025-70058 | An issue pertaining to CWE-295: An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests NVD description · AI analysis pending | 7.4 | <1% |
| — | ||
| CVE-2021-36686 | Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page. Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2021-27884 | Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used. NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2018-17574 | An issue was discovered in YMFE YApi 1.3.23. An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — |