Yes24 is a South Korean online retailer whose vulnerability footprint centers on its Viewer ActiveX control, a legacy browser plugin component. The observed exposure reflects characteristic weaknesses in unsigned or inadequately validated code delivery mechanisms, which present integrity risks in client-side download and execution flows. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yes24 over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12809HIGH Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the ar | Aug 15, 2019 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yes24.
Media articles that mention a CVE ID that affects a product developed by Yes24 — matched by CVE ID, not by vendor name.