Yonyou maintains a focused portfolio of enterprise resource planning and business management applications widely deployed across Chinese and Asian organizations, with a relatively narrow but strategically important footprint. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the vendor's centrality to financial and operational systems. The exposure recurs across flagship products such as KSOA, YonBIP, and its Ufida ERP suite through a consistent pattern of injection-class weaknesses—SQL injection, cross-site scripting, code injection, and improper input neutralization—alongside dangerous file-upload handling that are endemic to web-facing business applications. Defenders should treat this vendor's advisories as high-priority for any organization running its ERP or financial suite; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yonyou over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26263MEDIUM Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp. | Mar 25, 2022 | 6.1 | 57 | NO | YES |
CVE-2026-1130CRITICAL A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_plan.jsp of the component HTTP GET Parameter Handler. This mani | Jan 19, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-1123CRITICAL A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp of the component HTTP GET Parameter Handler. Such manipulatio | Jan 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-1122CRITICAL A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp of the component HTTP GET Parameter Handler. This manipulat | Jan 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-1121CRITICAL A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Parameter Handler. The manipulation | Jan 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-1179CRITICAL A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter Handler. The manipulation of the | Jan 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-1177CRITICAL A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /kmf/save_folder.jsp of the component HTTP GET Parameter H | Jan 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-1131CRITICAL A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parameter Handler. Such manipulation | Jan 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-1129CRITICAL A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GET Parameter Handler. The manipu | Jan 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-1120CRITICAL A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component HTTP GET Parameter Handler. The | Jan 18, 2026 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yonyou.
Media articles that mention a CVE ID that affects a product developed by Yonyou — matched by CVE ID, not by vendor name.