Skip to content
Noroxi

ymfe records

7 published records for vendor ymfe.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
28.6%
Median publish → KEV
No record has entered KEV

All records

7 records
  • An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denial

    HighCVSS 7.5No exploitEPSS 0%

    ymfe · yapiMar 9, 2026

  • A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute

    HighCVSS 7.4No exploitEPSS 0%

    Apr 30, 2024

  • An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0.

    HighCVSS 7.4No exploitEPSS 0%

    ymfe · yapiFeb 23, 2026

  • An issue was discovered in YMFE YApi 1.3.23.

    MediumCVSS 5.4No exploitEPSS 1%

    ymfe · yapiSep 28, 2018

  • Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.

    MediumCVSS 5.4No exploitEPSS 1%

    ymfe · yapiJan 26, 2023

  • An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v1.12.0.

    MediumCVSS 5.4No exploitEPSS 0%

    ymfe · yapiMar 9, 2026

  • Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens.

    MediumCVSS 5.1No exploitEPSS 0%

    ymfe · yapiMar 1, 2021