PatchSiren

yshopmall CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM yshopmall CVE published 2026-09-09

CVE-2026-75308

CVE-2026-75308 is a Cross Site Scripting (XSS) vulnerability in yshopmall version 3.3 or earlier. The vulnerability exists in the file upload endpoint /api/upload, which lacks file type validation, allowing attackers to upload malicious files. This could lead to potential XSS attacks, requiring defenders to assess exposure and prioritize verification and mitigation. The CVE record and NVD entry provide li [truncated]