Yopify operates a narrowly scoped product focused on providing a unified platform or service, with its documented vulnerability exposure centered on a single product line. The recurring pattern reflects information-disclosure weaknesses tied to policy configuration and access control, suggesting that the primary attack surface involves improper handling of sensitive data visibility and authorization boundaries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yopify over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-3211MEDIUM Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent purchase data of customers, all without user authorization. | Jan 15, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yopify.
Media articles that mention a CVE ID that affects a product developed by Yopify — matched by CVE ID, not by vendor name.