Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Yapi
(Ymfe)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 3 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-03-01 | CVE-2021-27884 | Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used. | Yapi | 5.1 | ||
2023-01-26 | CVE-2021-36686 | Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page. | Yapi | 5.4 | ||
2018-09-28 | CVE-2018-17574 | An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project. | Yapi | 5.4 |