Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-70059

    An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denial of service.

    Last Modified: Mar 13, 2026
    Published: Mar 09, 2026

    CVE-2025-70060

    An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v1.12.0.

    Last Modified: Mar 13, 2026
    Published: Mar 09, 2026

    CVE-2025-70058

    An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests

    Last Modified: Feb 26, 2026
    Published: Feb 23, 2026

    CVE-2024-33831

    A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the body field.

    Last Modified: Apr 15, 2026
    Published: Apr 30, 2024

    CVE-2021-36686

    Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.

    Last Modified: Apr 01, 2025
    Published: Jan 26, 2023
    Items Per Page
    Ymfe Vulnerabilities & Security CVEs | CVE-DB