MEDIUM
yshopmall
CVE published 2026-09-09
CVE-2026-75308
CVE-2026-75308 is a Cross Site Scripting (XSS) vulnerability in yshopmall version 3.3 or earlier. The vulnerability exists in the file upload endpoint /api/upload, which lacks file type validation, allowing attackers to upload malicious files. This could lead to potential XSS attacks, requiring defenders to assess exposure and prioritize verification and mitigation. The CVE record and NVD entry provide li [truncated]