CVE-2026-75308
EUVD-2026-7521009.09.2026, 22:18
yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
References