yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.
CVE-2026-75308
NONE
EPSS 0.14%
Updated Sep 10, 2026
yshopmall
CVE Details
CVE ID
CVE-2026-75308
Published Date
Sep 10, 2026
Vendor
yshopmall
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.14%
Likelihood of exploitation in next 30 days
Percentile:
3.4th percentile (higher than 3.4% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory