Yf Exam Project maintains a narrowly focused examination or assessment platform with a small but notable vulnerability footprint centered on its core exam product. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yf Exam Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26779CRITICAL CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE). | Mar 3, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-26780CRITICAL CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection. | Mar 2, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-25403HIGH CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in | Mar 3, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-25402HIGH CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, resulting in any file upload. | Mar 3, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yf Exam Project.
Media articles that mention a CVE ID that affects a product developed by Yf Exam Project — matched by CVE ID, not by vendor name.