Yeqifu's vulnerability footprint centers on warehouse-management and logistics software, including dedicated inventory systems and car-rental platforms that track and control access to physical and digital assets. The durable signal across its disclosures is a recurring pattern of access-control weaknesses—including improper privilege assignment, authorization bypasses, and path-traversal issues—that reflect the sensitivity of permission models in systems managing asset allocation and user roles. Defenders should prioritize access-control configurations and role-based permission audits for this vendor's products; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yeqifu over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2107HIGH A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDeleteLoginfo of the file | Feb 7, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-2106HIGH A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/deleteNotice/batchDel | Feb 7, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-2105HIGH A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of the file dataset\rep | Feb 7, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-2078HIGH A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermission/deletePermission of the fi | Feb 7, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-2076HIGH A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this vulnerability is the function addUser/updateUser/deleteUser of t | Feb 7, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-2075HIGH A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected is the function saveRolePermission of the file dataset\repos\wareho | Feb 7, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-0574HIGH A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse\src\main\java\com\ye | Jan 4, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-65879HIGH Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which | Dec 5, 2025 | 8.1 | 27 | NO | NO |
CVE-2026-2079HIGH A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addMenu/updateMenu/deleteMenu of the file dataset\ | Feb 7, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-2077HIGH A security vulnerability has been detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function addRole/updateRole/deleteRole | Feb 7, 2026 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yeqifu.
Media articles that mention a CVE ID that affects a product developed by Yeqifu — matched by CVE ID, not by vendor name.