CVE-2026-92463 is a high-severity vulnerability in yshop-crm, a customer relationship management system. The vulnerability has a CVSS score of 7.1 and allows authenticated back-office users without system:user:list permission to enumerate all users. This could potentially allow attackers with valid back-office credentials and a role with data scope ALL to retrieve sensitive user information.
CVE-2026-92458 is a missing authorization vulnerability in the StoreProductController onSale handler of yshop-crm through version 2.1.3. This allows authenticated back-office users to modify product sale status without proper permissions, potentially affecting product catalogs and inventory management. Defenders should assess exposure and verify proper permission checks are in place to prevent unauthorize [truncated]