Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Youlai

First CVE: Nov 26, 2025Active for: 1 yearTotal CVEs: 14
39.0
VTI Score
Medium

Youlai is a modestly represented vendor focused on e-commerce and application framework products, with a concentrated portfolio that includes its mall and boot platform components alongside web UI tooling. Vulnerabilities affecting the vendor skew toward serious outcomes with an elevated share reaching critical severity, and recur persistently through access-control weakness classes including improper authorization, incorrect privilege assignment, and missing authorization checks that characterize the vendor's core platform architecture. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Youlai over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 26, 2025
7 months ago
Most Recent CVE
Feb 27, 2026
149 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-3287CRITICAL
A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/co
Feb 27, 20269.831NONO
CVE-2025-55469CRITICAL
Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.
Nov 26, 20259.831NONO
CVE-2025-14085HIGH
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId lea
Dec 5, 20258.828NONO
CVE-2025-14051HIGH
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing man
Dec 4, 20258.828NONO
CVE-2025-14086HIGH
A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipulation of the argument openid re
Dec 5, 20258.827NONO
CVE-2025-15085HIGH
A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/c
Dec 25, 20258.126NONO
CVE-2025-55471HIGH
Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.
Nov 26, 20257.526NONO
CVE-2025-66735HIGH
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users
Dec 22, 20257.522NONO
CVE-2025-14052MEDIUM
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The ma
Dec 5, 20256.522NONO
CVE-2025-66736HIGH
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity
Dec 22, 20257.121NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
29%
50%
14%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low9 (64.3%)
High1 (7.1%)
None4 (28.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Youlai.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Youlai — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Youlai's Products

View all 2 CNAs →

Top CWEs