ymfe records
7 published records for vendor ymfe.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 28.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-295 Improper Certificate Validation1
- CWE-330 Use of Insufficiently Random Values1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2025-70059No exploit | An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denialymfe · yapi · CWE-400 | High7.5 | — | 0.3% | Mar 9, 2026 |
29Monitor | CVE-2024-33831No exploit | A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute CWE-80 | High7.4 | — | 0.5% | Apr 30, 2024 |
29Monitor | CVE-2025-70058No exploit | An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0.ymfe · yapi · CWE-295 | High7.4 | — | 0.2% | Feb 23, 2026 |
21Monitor | CVE-2018-17574No exploit | An issue was discovered in YMFE YApi 1.3.23.ymfe · yapi · CWE-79 | Medium5.4 | — | 0.7% | Sep 28, 2018 |
21Monitor | CVE-2021-36686No exploit | Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.ymfe · yapi · CWE-79 | Medium5.4 | — | 0.5% | Jan 26, 2023 |
21Monitor | CVE-2025-70060No exploit | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v1.12.0.ymfe · yapi · CWE-79 | Medium5.4 | — | 0.2% | Mar 9, 2026 |
20Monitor | CVE-2021-27884No exploit | Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens.ymfe · yapi · CWE-330 | Medium5.1 | — | 0.3% | Mar 1, 2021 |
- CVE-2025-7005930Monitor
An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denial
HighCVSS 7.5No exploitEPSS 0%ymfe · yapiMar 9, 2026
- CVE-2024-3383129Monitor
A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute
HighCVSS 7.4No exploitEPSS 0%Apr 30, 2024
- CVE-2025-7005829Monitor
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0.
HighCVSS 7.4No exploitEPSS 0%ymfe · yapiFeb 23, 2026
- CVE-2018-1757421Monitor
An issue was discovered in YMFE YApi 1.3.23.
MediumCVSS 5.4No exploitEPSS 1%ymfe · yapiSep 28, 2018
- CVE-2021-3668621Monitor
Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.
MediumCVSS 5.4No exploitEPSS 1%ymfe · yapiJan 26, 2023
- CVE-2025-7006021Monitor
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v1.12.0.
MediumCVSS 5.4No exploitEPSS 0%ymfe · yapiMar 9, 2026
- CVE-2021-2788420Monitor
Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens.
MediumCVSS 5.1No exploitEPSS 0%ymfe · yapiMar 1, 2021